CVE-2026-105294

Published: Ott 05, 2026 Last Modified: Ott 05, 2026
ExploitDB:
Other exploit source:
Google Dorks:
CRITICAL 9,1
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH 7,4
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none

Description

AI Translation Available

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.

15

External Control of System or Configuration Setting

Incomplete
Common Consequences
Security Scopes Affected:
Other
Potential Impacts:
Varies By Context
Applicable Platforms
Technologies: Not Technology-Specific, ICS/OT
View CWE Details
https://github.com/Legcord/Legcord
https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts#L296-L299
https://github.com/Legcord/Legcord/blob/v1.3.0/src/main.ts#L277-L307
https://github.com/Legcord/Legcord/issues/1163
https://www.vulncheck.com/advisories/legcord-1.1.0-through-1.3.0-chromium-switc…