Sceawere
Vulnerability Detail
CVE-2026-105294UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Legcord Configuration Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.4
- Creation Date
- 17h ago
- Vendor
- Legcord
- Product
- Legcord
- Attack Type
- External Control of System or Configuration Setting
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack Complexity
- HIGH
Narrative and Response
Description
Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.4",
"pubDate": "2026-10-05T01:16:28.923Z",
"pubdate": "2026-10-05T01:16:28.923Z",
"executiveSummary": "Legcord versions 1.1.0 through 1.3.0 are susceptible to a configuration injection vulnerability stemming from an insecure bridge between the web-rendered Discord interface and the underlying Electron application host. This vulnerability allows an attacker who successfully executes a Cross-Site Scripting (XSS) attack within the Discord client to manipulate the global application configuration via the window.legcord settings.setConfig method. By leveraging this bridge, an attacker can modify sensitive application parameters, most notably the additionalArguments array. This allows for the persistent injection of malicious command-line switches, such as --proxy-server and --ignore-certificate-errors, into the application launch sequence. The primary risk involves a complete compromise of the client's network traffic, enabling transparent interception, data exfiltration, and the subversion of TLS/SSL protections. Exploitation requires an initial XSS vector to execute arbitrary JavaScript within the context of the Discord page, granting the attacker the ability to reconfigure the host environment persistently. This vulnerability creates a critical security bypass, as the modified configuration persists across application restarts, effectively turning a transient client-side script execution into a permanent network-level man-in-the-middle capability.",
"technicalDetails": "The root cause of this vulnerability lies in the improper sanitization and lack of origin validation within the window.legcord bridge provided to the Discord web view. The bridge exposes the setConfig function, which serves as a privileged interface for modifying Legcord's internal configuration state. Because this interface lacks adequate access control, any script executing within the Discord page—such as one injected via XSS—can invoke this function to overwrite arbitrary configuration keys.\nThe exploitation flow begins with the execution of a malicious payload within the Discord client environment. Once the attacker has gained JavaScript execution privileges, they interface with the bridge to target the settings object. Specifically, the attacker invokes window.legcord settings.setConfig('additionalArguments', [...]), where the array contains malicious CLI arguments. By injecting switches like --proxy-server=http://attacker-controlled-proxy:port and --ignore-certificate-errors, the attacker instructs the underlying Chromium engine to route all outbound traffic through their infrastructure.\nThe impact of this injection is severe because these arguments are persisted within the application's configuration storage. Upon the next application launch, the Electron process reads these parameters and applies them to the Chromium environment. Consequently, the proxy settings take effect before the client establishes any connection to Discord's servers, allowing for full interception of authentication tokens, message content, and sensitive user data. The inclusion of --ignore-certificate-errors ensures that the client will not warn the user if the attacker presents a fraudulent, self-signed certificate during the TLS handshake, effectively neutralizing HTTPS protections.\nThe vulnerable component is the Electron-to-renderer bridge defined by Legcord for interacting with the application backend. Versions 1.1.0 through 1.3.0 are affected. There are no authentication requirements within the bridge itself; the environment assumes that any code running in the renderer is trusted, failing to implement a whitelist or origin-based validation for configuration modification. Because the attacker utilizes a client-side execution path, there is no requirement for elevated local privileges initially, provided the attacker can achieve persistent code injection within the Discord instance."
}