CVE-2026-105293

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-05: 110-05
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft

    🔐 Legcord Cluster — 2 CVEs, Discord Script Escapes Sandbox to Achieve RCE and Traffic Interception Two vulnerabilities in Legcord, an open-source Discord client, were disclosed on October 4, 2026. 🔗 https://threataft.com/articles/legcord-cluster-cve-2026-105293-105294?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #Legcord #Discord #CVE

    0000032
    46 followersView on X

Explore more