CyberRota Analysis
AI-GeneratedLegcord versions 1.1.0 to 1.3.0 are vulnerable to a path traversal issue that permits attackers to manipulate theme IPC handlers, enabling them to execute local commands and access files outside the intended themes directory. This vulnerability can be exploited through cross-site scripting (XSS) attacks, allowing for significant impacts such as unauthorized file deletion and execution of local executables. Organizations using affected versions of Legcord should prioritize patching this vulnerability to mitigate potential exploitation risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.