External risk intelligence

Legcord Path Traversal via Theme IPC Handlers

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-105293

This vulnerability affects a client-side application running locally on a user's machine. The attack requires the execution of arbitrary scripts within the specific context of the client application, which is not a public-facing service, API, or network-accessible infrastructure.

Path Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A path traversal vulnerability has been identified in the Legcord application, allowing malicious scripts to execute commands and manipulate files outside of designated directories. This issue arises from unvalidated theme IDs within the application's theme handling processes. The primary concern is to confirm if this specific application is in use within the organization and, if so, to understand the potential exposure.

  • Unvalidated themes allow script execution and file manipulation.
  • Confirms if this client-side application is relevant.
  • Assess potential exposure and relevance to our environment.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this by first executing script within the Discord origin, potentially through a cross-site scripting (XSS) attack. This script can then abuse specific theme handling functions, such as installing or uninstalling themes, to bypass security restrictions. By manipulating theme identifiers, the attacker can target files and directories outside the intended themes folder, leading to the execution of local commands, deletion of files, or writing arbitrary data.

  • Requires script execution within Discord origin.
  • Triggers via unvalidated theme identifiers in IPC handlers.
  • Leads to arbitrary code execution and file manipulation.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, attackers with script execution capabilities within the Discord origin could abuse theme handlers to write files outside the intended directory, recursively delete directories, or launch local executables.

  • Local executables could be launched.
  • Directories could be recursively deleted.
  • Files could be written outside themes.

Operational Fix

Recommended remediation, mitigation, and detection steps

Understanding who should act requires identifying the owners of the Legcord application and its deployment. The first practical step is to locate all instances of Legcord, determine if they are business-critical or exposed to risk, and then assign an accountable owner to plan remediation, potentially coordinating with the vendor.

  • Application owners are responsible.
  • Verify Legcord installation and reachability.
  • Plan vendor-coordinated remediation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Legcord?

Legcord is a modified, third-party client for the Discord platform. It allows users to customize their experience with themes and plugins. Because it functions as a wrapper around the official Discord web interface, it manages local IPC (Inter-Process Communication) handlers to bridge the gap between the web content and the user's local operating system.

What does path traversal mean for CVE-2026-105293?

This vulnerability, classified as CWE-22, means the application fails to properly sanitize input when handling theme IDs. Normally, theme files should only exist within a specific 'themes' folder. Because of this flaw, an attacker can use specially crafted IDs to 'traverse' or escape that directory, tricking the software into interacting with other sensitive files on your machine.

How does an attacker trigger this vulnerability?

An attacker cannot trigger this simply by sending a message or visiting a link. They must first be able to run arbitrary scripts within the Discord origin—typically through a cross-site scripting (XSS) exploit. If they achieve that, they can then send malicious requests to the internal IPC handlers to manipulate files or launch local executables.

Do I need to worry if I use Legcord?

According to Halo Surface Signal, this vulnerability is considered 'Very unlikely' to be exploited in most environments. Since Legcord is a local client-side application rather than a public-facing web server, it lacks the internet-exposed attack surface that attackers typically target for automated exploitation.

When should I take action regarding this CVE?

If your organization uses Legcord, the first step is to locate all instances of the application on your systems. Determine if the software is still required for business operations and identify an owner for it. Once located, verify the version and prepare to update or restrict the software based on guidance from the project's official repository.

References