Skip to content
eastbaycyber

CVE-2026-105293: Legcord Theme IPC Path Traversal

CVSS · High
8.1
In CISA KEV
No
Published
Oct 5
CVE explainers 9 min read
Security Research Desk Source-checked
Auto-checked against the official CVE record · Human-reviewed after publishing · Updated 2026-10-05
Threat Intelligence
1GitHub refs
▲ Escalation ViewOne CVE, briefed at three altitudes — skim the Brief, weigh the Impact, or work the Runbook. The way a SOC actually reads it.
CISOBrief · 30-second brief

TL;DR - Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme-related Electron IPC handlers. - Script executing in the Discord origin may write files, delete directories, or launch local executables. - No fixed version or verified public standalone PoC is known; CISA KEV does not list this CVE.

Vulnerability at a Glance

CVE-2026-105293 is a high-severity Legcord vulnerability involving path traversal in an Electron-based Discord client. The issue affects theme-related IPC handlers that process attacker-controlled theme identifiers without adequately constraining filesystem paths to the intended themes directory.

Field Value
CVE ID CVE-2026-105293
Affected product Legcord
Affected versions 1.1.0 through 1.3.0, inclusive
CVSS base score 8.1 High
CVSS vector Not exposed in the retrieved NVD record; confirm directly in the NVD record before using a vector string
Attack vector Not fully specified by the available record; exploitation requires script executing in the Discord origin and access to exposed IPC functionality
Authentication required Not explicitly stated in the available record
Patch available No confirmed fixed release identified
CISA KEV status Not listed
Public standalone PoC None verified in the reviewed sources

The project’s download page identified Legcord 1.3.0 as the latest version in the research snapshot. That version is within the affected range and must not be treated as a remediation. Organizations should inventory the installed version instead of assuming that the latest visible download resolves the issue.

Analyst’s Take: Treat 1.3.0 as vulnerable until a release explicitly fixes validation in the theme IPC handlers. The most immediate defensive value comes from confirming installed versions, restricting script execution in the Discord origin, and watching for Legcord-driven file and process activity.

What Is This Vulnerability?

The vulnerability is caused by insufficient validation of theme identifiers passed to Electron IPC handlers. The affected functionality includes themes.folder, themes.uninstall, and themes.install. If a supplied identifier is interpreted as part of a filesystem path without strict validation and canonicalization, traversal sequences can cause an operation to address files or directories outside the intended themes directory.

The reported consequences extend beyond unauthorized theme modification. Depending on which handler is reached and how the resulting path is processed, an attacker may be able to write files outside the themes directory, recursively delete directories, or launch local executables. These operations create a potential path from renderer-level script execution to significant local-system impact.

The precondition described by the NVD record is important. The attacker needs script to execute in the Discord origin, such as through an XSS condition or another mechanism that places attacker-controlled JavaScript in the relevant renderer context. The available evidence does not characterize this as an unauthenticated remote vulnerability that can be exploited against every Legcord installation without that script-execution condition.

Technical Notes

The NVD references the following v1.3.0 source locations:

src/common/themes.ts  lines 269-276
src/discord/ipc.ts    lines 201-206

The relevant review question is whether user-controlled theme identifiers are resolved and then verified to remain beneath the approved themes directory. A secure implementation should reject traversal, absolute paths, unexpected separators, symlink escapes, and identifiers that resolve outside the intended directory after canonicalization.

AnalystImpact · assess the risk

Who Is Affected?

The affected product is Legcord, maintained in the Legcord/Legcord project. The vulnerable range is Legcord 1.1.0 through 1.3.0, inclusive. The available research does not identify operating-system-specific exclusions, so administrators should assume that installations in this range require review whether they run on Windows, macOS, or Linux.

Legcord installations that do not expose or use the affected theme functionality may have a lower practical attack surface, but the vulnerability should not be dismissed solely because users do not routinely install themes. The issue is in IPC handlers, and the relevant security boundary is the renderer’s ability to invoke those handlers with attacker-controlled values.

No confirmed fixed version was identified in the retrieved primary sources. In particular, 1.3.0 is not a fixed version. Administrators should not report the issue as remediated based only on upgrading to the latest version listed on the project download page.

CVSS Score Breakdown

NVD assigns CVE-2026-105293 a CVSS base score of 8.1, High. The score indicates serious potential security consequences, but it does not describe every operational precondition. Here, the required script execution in the Discord origin is central to risk assessment.

The retrieved NVD response supplied the score but did not expose the CVSS vector string. Consequently, the individual values for attack vector, attack complexity, privileges required, user interaction, scope, confidentiality, integrity, and availability cannot be reliably reconstructed without guessing. Security teams should retrieve the authoritative NVD record before importing the vector into governance, ticketing, or risk-scoring systems.

CVSS element Confirmed interpretation
Base score 8.1, High
Attack vector Exact CVSS value not available in the retrieved record
Privileges required Exact CVSS value not available in the retrieved record
User interaction Exact CVSS value not available in the retrieved record
Scope Exact CVSS value not available in the retrieved record
Confidentiality, integrity, availability Exact component values not available in the retrieved record

The practical impact is nevertheless clear: successful abuse may affect filesystem integrity and availability and may enable local executable launch. Those consequences justify prioritizing containment and monitoring while awaiting a confirmed upstream fix.

Exploitation Status

CVE-2026-105293 is not listed in CISA’s Known Exploited Vulnerabilities catalog. There is therefore no CISA confirmation of exploitation in the wild as of the supplied research date. This status does not prove that exploitation is impossible or that private exploitation has not occurred; it only means that CISA has not added the CVE to KEV.

No verified, standalone public exploit repository or working proof of concept was identified in the reviewed sources. The NVD description and source references provide enough technical detail to understand the affected handlers and likely impact, but they do not establish the existence of a complete weaponized exploit.

A public GitHub issue, issue #1163, is titled “Security report submitted: unvalidated IPC parameters in themes/config handlers (coordinating via MITRE, ticket 2099033).” Its existence should be treated as public vulnerability reporting, not as evidence of active exploitation or a reliable exploit PoC.

ResponderRunbook · act now

How to Detect It

Detection should focus on the precondition and consequences: unexpected script execution in the Discord renderer, unusual calls into theme functionality, writes outside the normal Legcord themes directory, recursive deletion, and child processes launched by Legcord. Endpoint telemetry is likely to be more useful than a network signature because the reported operations occur locally through Electron IPC.

The exact legitimate theme-directory path varies by operating system and installation method, and the supplied record does not define a universal path. Security teams should first identify the installation and profile paths used in their environment, then alert on Legcord-associated processes accessing unrelated user, system, startup, or application directories.

For suspected compromise on macOS, follow a structured collection process such as this digital forensics guide and preserve endpoint telemetry before removing the application.

Technical Notes

On Linux systems using auditd, administrators can monitor the Legcord executable after identifying its real path. The following example is a starting point and must be adapted to the local installation:

# Replace /opt/Legcord/legcord with the verified executable path.
sudo auditctl -w /opt/Legcord/legcord -p x -k legcord_exec

# Review Legcord execution and related audit activity.
sudo ausearch -k legcord_exec -i
sudo ausearch -ts today -i | grep -Ei 'legcord|themes|execve|unlink|rename|openat'

A useful behavioral query in an endpoint platform is to identify Legcord or its Electron child processes writing to locations outside the approved themes directory. Example pseudo-query logic is intentionally path-agnostic:

process.name in ("Legcord", "legcord", "electron")
and file.operation in ("create", "write", "rename", "delete")
and file.path not_under <approved_legcord_themes_directory>

Also alert when a Legcord process launches shells, scripting engines, installers, or unrelated native binaries. A child-process event such as Legcord -> cmd.exe, Legcord -> powershell.exe, Legcord -> bash, or Legcord -> sh is not proof of exploitation, but it is high-value triage evidence when paired with unexpected file activity.

Mitigation and Patching

There is no confirmed fixed version in the supplied primary-source research. The affected range remains 1.1.0 through 1.3.0, and upgrading to 1.3.0 does not resolve the issue. Administrators should monitor the Legcord repository, release notes, and advisory channels for a release that explicitly addresses validation in the theme IPC handlers.

Until a fix is confirmed, avoid using affected Legcord installations for sensitive accounts where practical. Restrict untrusted content and scripts from executing in the Discord origin, avoid loading untrusted themes, and consider removing Legcord from managed endpoints if the application is not essential. These controls reduce exposure but do not replace an upstream code fix.

If endpoint coverage is limited, organizations may evaluate a reputable malware scanner such as Get Bitdefender → as a supplementary check. Scanning does not patch the vulnerability and should not replace process, filesystem, and application telemetry.

If suspicious file writes, deletion, or process launches are confirmed, preserve evidence and follow your incident-response procedures. The first-hour ransomware response guide provides a useful framework for early containment and evidence preservation, even when ransomware has not been confirmed.

Technical Notes

A safe inventory check can identify installed Legcord versions without claiming that any version is patched:

# Linux example: inspect common package metadata and application paths.
find /opt "$HOME/.local" "$HOME/.config" -maxdepth 4 \
  \( -iname '*legcord*' -o -iname 'package.json' \) 2>/dev/null

# If a Legcord package directory is found, inspect its version.
grep -R '"version"' /path/to/legcord/package.json 2>/dev/null

Do not use a blind upgrade command that installs 1.3.0 and reports success as remediation. For temporary containment, stop the application and remove or quarantine it using the endpoint’s normal software-management process. On a Linux host where Legcord is running as a user process, an administrator can use:

pkill -f '[Ll]egcord'

If the application provides a supported theme-disable setting, disable theme installation, import, and management until a verified fix is available. Do not manually delete arbitrary directories as a workaround; the vulnerability’s reported impact includes recursive deletion, so containment changes should be controlled, logged, and tested.

References

The primary vulnerability record is the NVD API entry for CVE-2026-105293:

Additional project and advisory material includes the public security report and the project’s download page. These sources should be rechecked before publication or remediation decisions because release and patch status can change after the CVE’s initial publication:

Start by identifying every Legcord installation in the affected range and contain systems where script can execute in the Discord origin. Until an upstream release explicitly fixes the theme IPC validation, use endpoint telemetry to catch writes, deletions, and child-process launches that fall outside normal Legcord behavior.

This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.

Last verified: 2026-10-05

Disclaimer: This article may contain affiliate links. We earn a commission on qualifying purchases at no extra cost to you.