Legcord Discord client hit by two CVEs: XSS-to-RCE and persistent traffic interception
Two vulnerabilities were found in the Legcord Discord client: CVE-2026-105293 (CVSS 8.1) uses path traversal in theme IPC handlers to escape the Electron sandbox and execute code, while CVE-2026-105294 (CVSS 7.4) injects proxy settings that persistently route all traffic through an attacker's proxy with TLS validation disabled. No fixed version was available at publication; users are advised to upgrade past 1.3.0 and check their config.
- CVE-2026-105293 (CVSS 8.1): path traversal in themes.install/uninstall/folder leads to RCE
- CVE-2026-105294 (CVSS 7.4): setConfig without allowlist injects --proxy-server and --ignore-certificate-errors
- Injected proxy settings persist to disk and apply on every Legcord launch
- Both attacks require Discord-origin XSS; no fix was available at publication
Read next
Security