---
id: CVE-2026-105293
title: >-
  Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme
  IPC handlers that allows script in the Discord page to escape the themes
  directory via unvalidated theme ids
summary: >-
  Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme
  IPC handlers that allows script in the Discord page to escape the themes
  directory via unvalidated theme ids. Attackers running script in the Discord
  origin, su…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: Legcord
product: Legcord
affected:
  - Legcord >= 1.1.0 <= 1.3.0
published: '2026-10-05'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T01:16:28.780'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105293'
references:
  - url: 'https://github.com/Legcord/Legcord'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Legcord/Legcord/blob/v1.3.0/src/common/themes.ts#L269-L276
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts#L201-L206
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Legcord/Legcord/issues/1163'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/legcord-1.1.0-through-1.3.0-path-traversal-via-theme-ipc-handlers
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-05T01:08:41.782Z'
---

## Overview

Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, can abuse themes.folder, themes.uninstall, and themes.install to launch local executables, recursively delete directories, and write files outside the themes directory.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
