chiprook
← Security
SecurityOctober 5, 2026, 20:08

Legcord Discord client hit by two CVEs: XSS-to-RCE and persistent traffic interception

Two vulnerabilities were found in the Legcord Discord client: CVE-2026-105293 (CVSS 8.1) uses path traversal in theme IPC handlers to escape the Electron sandbox and execute code, while CVE-2026-105294 (CVSS 7.4) injects proxy settings that persistently route all traffic through an attacker's proxy with TLS validation disabled. No fixed version was available at publication; users are advised to upgrade past 1.3.0 and check their config.

Legcord Discord client hit by two CVEs: XSS-to-RCE and persistent traffic interception
#Legcord#Discord#Electron
Read next
Security

HashiCorp Vault RCE Flaw Persists as OpenBao Ships Patches

Security

x47.c Windows botnet uses xAI Grok for persistence and AI credit draining

Security

NIST FRTE 1:1 update shows shifting leaders, persistent demographic disparities

Science

Ukraine Intercepts 90% of Propeller Shaheds but Only 57% of Jet-Powered Ones