External risk intelligence

Legcord Configuration Injection Allows Discord XSS Proxying

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-105294

Legcord is a client-side application (a Discord client modification). It operates locally on a user's machine and does not act as a public-facing server, gateway, or internet-exposed service, making it inherently unlikely to be reachable from the public internet.

Cross-site Scripting

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A configuration injection vulnerability exists in Legcord versions 1.1.0 through 1.3.0, allowing malicious scripts to modify client settings. This could enable attackers to redirect all client traffic through an interception proxy by exploiting a Discord Cross-Site Scripting (XSS) vulnerability. Given Legcord is a client-side application and not internet-exposed, the primary concern is confirming its relevance and any potential local exposure.

  • Malicious scripts can change client settings.
  • This could route all traffic through a proxy.
  • Confirm relevance and exposure for this tool.

Attack Path

How an attacker could exploit the issue

An attacker could first compromise a user's Discord client through cross-site scripting (XSS) to inject malicious script. This script would then target a configuration setting within the Legcord application, allowing the attacker to modify critical application switches. By manipulating these settings, an attacker could reroute all client traffic through a proxy they control, potentially leading to data interception and manipulation.

  • Requires an existing Discord XSS vulnerability.
  • Script in Discord page writes any config key.
  • Enables traffic interception and manipulation.

Live Threat

Current exploitation, exposure, and threat context

A configuration injection vulnerability could allow scripts within the Discord page to write arbitrary configuration keys, potentially enabling an attacker to inject malicious switches into the Legcord client. This could reroute all client network traffic through an interception proxy when supported by the advisory.

  • Client traffic could be rerouted.
  • Via Discord XSS and Legcord settings.
  • All client traffic may be intercepted.

Operational Fix

Recommended remediation, mitigation, and detection steps

Given that Legcord is a client-side application, the primary responsibility likely falls to individual users or endpoint security teams to manage installations and configurations. The first practical step is to identify all endpoints where Legcord is deployed, assess the risk based on user privileges and network exposure, and then coordinate with users for remediation or mitigation actions.

  • Identify affected users and endpoints.
  • Verify user impact and configuration.
  • Plan user-level remediation or mitigation.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Legcord and how is it used?

Legcord is a modified Discord client application that extends the base software's functionality. It is designed to run locally on a user's machine, providing additional features and interface customizations beyond the standard Discord experience. Because it operates as a desktop client rather than a server-side service, it is installed and managed directly by the user on their personal device.

What does configuration injection mean for CVE-2026-105294?

This vulnerability, classified as External Control of System or Configuration Setting (CWE-15), means an unauthorized party can force the software to accept unintended settings. In this specific case, the Legcord bridge allows a script running within the Discord environment to overwrite internal configuration keys, granting an attacker the ability to modify how the application launches and behaves.

Does this vulnerability trigger automatically when using Legcord?

No, the vulnerability does not trigger through normal, everyday usage of the application. It requires a successful Cross-Site Scripting (XSS) attack against the Discord client first. If a malicious script cannot be executed within the Discord interface, the injection path remains closed and the application's configuration settings cannot be manipulated via this specific flaw.

How relevant is this for my local machine according to Halo Surface Signal?

According to Halo Surface Signal, this vulnerability is considered very unlikely to be exploited from the public internet. Because Legcord is a client-side application that does not act as a public-facing server or gateway, it lacks the internet-exposed attack surface that remote attackers typically target, making the risk profile primarily local rather than network-based.

What should I do if I have Legcord installed?

Your first step should be to locate all machines where the software is currently deployed. Once you have an inventory of these endpoints, assess whether users have a need for this specific modification. Coordinate with users to ensure they are aware of the risk, and evaluate the necessity of the installation while waiting for updates that address the configuration bridge security.

References