Sceawere
Vulnerability Detail
CVE-2026-105293UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Legcord Theme Path Traversal
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 17h ago
- Vendor
- Legcord
- Product
- Legcord
- Attack Type
- Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-05T01:16:28.780Z",
"pubdate": "2026-10-05T01:16:28.780Z",
"executiveSummary": "Legcord versions 1.1.0 through 1.3.0 are susceptible to a critical path traversal vulnerability residing within the application's inter-process communication (IPC) handlers dedicated to theme management.\nThe vulnerability originates from improper input validation of theme identifiers, which permits unauthorized directory traversal beyond the designated themes directory.\nAn attacker who successfully executes arbitrary script within the Discord origin—typically through a Cross-Site Scripting (XSS) vector—can leverage this flaw to interact with the underlying operating system.\nThe impact is severe, granting an attacker the ability to perform arbitrary file system operations, including the deletion of recursive directory structures, the writing of malicious files to arbitrary locations, and the execution of local binaries.\nThis represents a significant escalation of privilege from a web-origin script execution to local system command execution, posing a critical threat to the integrity and confidentiality of the host environment.\nNo specific authentication is required beyond the initial script execution capability within the application context.",
"technicalDetails": "The vulnerability is rooted in the insecure implementation of IPC handlers responsible for theme lifecycle management, specifically within the themes.folder, themes.uninstall, and themes.install functions.\nIn these handlers, the application fails to perform adequate sanitization or normalization on the theme ID parameters provided by the frontend. By supplying crafted strings containing directory traversal sequences (e.g., ../), an attacker can break out of the intended themes application directory.\nBecause Legcord utilizes Electron, the IPC bridge facilitates communication between the renderer process (the Discord origin) and the privileged main process. The flawed handlers directly expose file system APIs to the renderer process without enforcing a strict allow-list or path validation check against the base directory.\nThe attack flow proceeds as follows: First, an attacker injects a malicious script into the Discord page, potentially via a compromised plugin or XSS. Second, this script invokes the exposed IPC methods, passing a malicious path as a theme ID. Third, the main process, acting with the privileges of the user running Legcord, resolves the traversal sequence to access restricted files or directories on the host machine.\nExploitation allows for three primary post-exploitation primitives: (1) Arbitrary file writes, which can be used to overwrite legitimate configuration files or drop malicious executables into startup folders; (2) Recursive directory deletion, which facilitates the destruction of user data or application dependencies; and (3) Execution of local binaries, leveraging the ability to write or manipulate files to trigger command execution.\nGiven that the IPC handlers are exposed to any script running within the Discord origin, the barrier to entry is limited to the ability to execute JavaScript within that context. The vulnerability does not require prior authentication, as the execution of the application code itself is the primary requirement for exposure. The scope of the attack is limited only by the permissions of the operating system user account running the Legcord client."
}