OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-105294

HIGH · CVSS 7.4 EPSS 0.19% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-05 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Legcord versions 1.1.0 to 1.3.0 are vulnerable to a configuration injection flaw that permits attackers to manipulate configuration settings through a cross-site scripting (XSS) exploit on Discord. This vulnerability can lead to the persistent routing of client traffic through an interception proxy, compromising user privacy and security. Organizations utilizing Legcord should prioritize immediate remediation to mitigate the risk of traffic interception and potential data breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-105294
Severity
HIGH
CVSS
7.4
EPSS
0.19%

Original NVD Description

Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.