PatchSiren cyber security CVE debrief
CVE-2026-105293 Legcord CVE debrief
A critical vulnerability exists in Legcord versions 1.1.0 through 1.3.0, allowing attackers to execute scripts in the Discord page and escape the themes directory via unvalidated theme IDs. This path traversal vulnerability enables attackers to launch local executables, recursively delete directories, and write files outside the themes directory. The vulnerability is confirmed in these versions, and defenders should assess their exposure, especially for internet-facing deployments, and prioritize remediation.
- Vendor
- Legcord
- Product
- Unknown
- CVSS
- CRITICAL 9.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-05
- Original CVE updated
- 2026-10-05
- Advisory published
- 2026-10-05
- Advisory updated
- 2026-10-05
Who should care
Defenders responsible for Legcord installations, especially those with exposed or internet-facing deployments, should assess their exposure and prioritize remediation. Discord users and administrators may also need to be aware of potential risks.
Why it matters
CVE-2026-105293 is a critical path traversal vulnerability in Legcord versions 1.1.0-1.3.0, allowing attackers to execute scripts and manipulate files outside the themes directory. Defenders should prioritize remediation, especially for exposed installations, and verify their Legcord versions.
- Potential for attackers to execute arbitrary code on the host system.
- Ability for attackers to modify or delete files outside the themes directory.
- Risk of privilege escalation or lateral movement within the network.
- Need for defenders to verify and remediate vulnerable Legcord installations.
Technical summary
The vulnerability exists in the theme IPC handlers of Legcord, allowing script execution in the Discord page to escape the themes directory. Attackers can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory. This critical path traversal vulnerability enables attackers to execute scripts and manipulate files outside the themes directory, posing a significant risk to Legcord installations, especially those exposed or internet-facing.
Defensive priority
High priority remediation is recommended for Legcord users, especially those with exposed or internet-facing installations.
Recommended defensive actions
- Immediately update Legcord to a version outside the vulnerable range (1.1.0-1.3.0) if possible.
- Restrict access to the Discord page and theme installation functionality.
- Monitor for suspicious activity related to theme installation and file system modifications.
- Implement additional security measures to prevent script execution in the Discord origin.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
Evidence notes
The vulnerability is confirmed in Legcord versions 1.1.0 through 1.3.0. Official source references include GitHub repositories and a Vulncheck advisory. Evidence is limited to public sources and may not reflect the full scope or impact. Defenders should verify Legcord versions and review source references for further details. The CVE record and NVD detail page provide additional context.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105293 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105293
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105293 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105293
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/Legcord/Legcord
-
Source reference
Unverified legacy reference
URL: https://github.com/Legcord/Legcord/blob/v1.3.0/src/common/themes.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts
-
Source reference
Unverified legacy reference
URL: https://github.com/Legcord/Legcord/issues/1163
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/legcord-1.1.0-through-1.3.0-path-traversal-via-theme-ipc-handlers
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.