PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105293 Legcord CVE debrief

A critical vulnerability exists in Legcord versions 1.1.0 through 1.3.0, allowing attackers to execute scripts in the Discord page and escape the themes directory via unvalidated theme IDs. This path traversal vulnerability enables attackers to launch local executables, recursively delete directories, and write files outside the themes directory. The vulnerability is confirmed in these versions, and defenders should assess their exposure, especially for internet-facing deployments, and prioritize remediation.

Vendor
Legcord
Product
Unknown
CVSS
CRITICAL 9.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-05
Original CVE updated
2026-10-05
Advisory published
2026-10-05
Advisory updated
2026-10-05

Who should care

Defenders responsible for Legcord installations, especially those with exposed or internet-facing deployments, should assess their exposure and prioritize remediation. Discord users and administrators may also need to be aware of potential risks.

Why it matters

CVE-2026-105293 is a critical path traversal vulnerability in Legcord versions 1.1.0-1.3.0, allowing attackers to execute scripts and manipulate files outside the themes directory. Defenders should prioritize remediation, especially for exposed installations, and verify their Legcord versions.

  • Potential for attackers to execute arbitrary code on the host system.
  • Ability for attackers to modify or delete files outside the themes directory.
  • Risk of privilege escalation or lateral movement within the network.
  • Need for defenders to verify and remediate vulnerable Legcord installations.

Technical summary

The vulnerability exists in the theme IPC handlers of Legcord, allowing script execution in the Discord page to escape the themes directory. Attackers can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory. This critical path traversal vulnerability enables attackers to execute scripts and manipulate files outside the themes directory, posing a significant risk to Legcord installations, especially those exposed or internet-facing.

Defensive priority

High priority remediation is recommended for Legcord users, especially those with exposed or internet-facing installations.

Recommended defensive actions

  • Immediately update Legcord to a version outside the vulnerable range (1.1.0-1.3.0) if possible.
  • Restrict access to the Discord page and theme installation functionality.
  • Monitor for suspicious activity related to theme installation and file system modifications.
  • Implement additional security measures to prevent script execution in the Discord origin.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The vulnerability is confirmed in Legcord versions 1.1.0 through 1.3.0. Official source references include GitHub repositories and a Vulncheck advisory. Evidence is limited to public sources and may not reflect the full scope or impact. Defenders should verify Legcord versions and review source references for further details. The CVE record and NVD detail page provide additional context.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105293 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105293

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105293 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105293

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.