OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105293

HIGH · CVSS 8.1 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Legcord versions 1.1.0 to 1.3.0 are vulnerable to a path traversal issue that permits attackers to manipulate theme IPC handlers, enabling them to execute local commands and access files outside the intended themes directory. This vulnerability can be exploited through cross-site scripting (XSS) attacks, allowing for significant impacts such as unauthorized file deletion and execution of local executables. Organizations using affected versions of Legcord should prioritize patching this vulnerability to mitigate potential exploitation risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105293
Severity
HIGH
CVSS
8.1
EPSS
0.38%

Original NVD Description

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.