CVE-2026-105294
Received Received - Intake

Legcord Configuration Injection via Discord XSS

Vulnerability report for CVE-2026-105294, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: VulnCheck

Description

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
legcord legcord From 1.1.0 (inc) to 1.3.0 (inc)
legcord legcord From 1.2.4 (inc) to 1.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-15 One or more system settings or configuration elements can be externally controlled by a user.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a configuration injection flaw in Legcord versions 1.1.0 through 1.3.0. It allows scripts running in the Discord page to manipulate the application's configuration via the window.legcord.settings.setConfig bridge. Attackers can exploit a cross-site scripting (XSS) vulnerability in Discord to set command-line switches like --proxy-server and --ignore-certificate-errors, routing all client traffic through an interception proxy.

Detection Guidance

Check Legcord configuration files for unexpected command-line switches like --proxy-server or --ignore-certificate-errors. Inspect network traffic for unauthorized proxy usage. Monitor Discord page scripts for suspicious setConfig calls to window.legcord.settings.

Impact Analysis

This vulnerability allows attackers to intercept and monitor all your Discord client traffic by routing it through a proxy. They can also bypass security settings, potentially leading to unauthorized access to sensitive data or execution of malicious scripts on your system.

Compliance Impact

This vulnerability could lead to unauthorized interception of user traffic via proxy routing, potentially exposing sensitive data. For GDPR, this may violate principles of data protection and user consent. For HIPAA, it risks unauthorized access to protected health information if exploited in healthcare environments.

Mitigation Strategies

Update Legcord to the latest version beyond 1.3.0 if available. Disable or remove Legcord until patched. Block suspicious network traffic at the firewall level. Review and remove any unauthorized proxy configurations in system settings.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105294. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart