CVE-2026-105293

Source
https://cve.org/CVERecord?id=CVE-2026-105293
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105293.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2026-105293
Published
2026-10-05T00:44:18Z
Modified
2026-10-05T10:45:17Z
Severity
  • 9.2 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Legcord 1.1.0 through 1.3.0 Path Traversal via Theme IPC Handlers
Details

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-22"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105293.json"
}
References

Affected packages

Git / github.com/legcord/legcord

Affected ranges

Type
GIT
Repo
https://github.com/legcord/legcord
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "1.1.0"
        },
        {
            "last_affected": "1.3.0"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v1.*
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.1.5
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-105293.json"