CVE-2026-105293 PUBLISHED

Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers

Assigner: VulnCheck
Reserved: 05.10.2026 Published: 05.10.2026 Updated: 05.10.2026

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.2

Product Status

Vendor Legcord
Product Legcord
Versions Default: unaffected
  • affected from 1.1.0 to 1.3.0 (incl.)

Credits

  • Siyang Wu finder

References

Problem Types

  • Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE