Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105293— Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers

Quick assessment

Affected
Legcord Legcord
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Legcord 1.1.0 至 1.3.0 版本中存在一个路径遍历漏洞,该漏洞位于主题 IPC(进程间通信)处理器中,允许通过未经验证的主题 ID,使 Discord 页面中的脚本突破主题目录的限制。攻击者若在 Discord 原始来源中执行脚本(例如通过跨站脚本攻击 XSS),可利用 、 和 等功能,在主题目录之外执行本地可执行程序、递归删除目录以及写入任意文件。

CVSS 8.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105293

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers
Source: CVE Program / CVE List V5
Vulnerability Description
Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Legcord Legcord 1.1.0 ~ 1.3.0 -

II. Public POCs for CVE-2026-105293

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105293

请登录查看更多情报信息。

Other References for CVE-2026-105293 (5)

IV. Related Vulnerabilities

V. Comments for CVE-2026-105293

No comments yet


Leave a comment