PatchSiren

Legcord CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Legcord CVE published 2026-10-05

CVE-2026-105294

CVE-2026-105294 is a configuration injection vulnerability in Legcord versions 1.1.0 through 1.3.0. This vulnerability allows an attacker to inject scripts via the Discord page, enabling them to write any config key using the window.legcord.settings.setConfig bridge. Consequently, attackers can exploit a Discord XSS to set additionalArguments, which can add --proxy-server and --ignore-certificate-errors s [truncated]

CRITICAL Legcord CVE published 2026-10-05

CVE-2026-105293

A critical vulnerability exists in Legcord versions 1.1.0 through 1.3.0, allowing attackers to execute scripts in the Discord page and escape the themes directory via unvalidated theme IDs. This path traversal vulnerability enables attackers to launch local executables, recursively delete directories, and write files outside the themes directory. The vulnerability is confirmed in these versions, and defen [truncated]