
Node.js module resolution on Windows allows local privilege escalation when applications search C:\node_modules. Discord desktop app (CVE-2026-0776) remains unpatched - any user can plant malicious modules for code execution on app launch. #DFIR_Radar
Post summary
A Windows‑specific local privilege escalation flaw in Node.js module resolution allows malicious modules to execute code in the Discord app, which remains unpatched and poses a potential risk, but no PoC, tool, or active exploitation is reported.

