Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 Oct 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy. | |
| Title | Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig | |
| Weaknesses | CWE-15 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T00:44:19.284Z
Reserved: 2026-10-05T00:19:08.246Z
Link: CVE-2026-105294
No data.
Status : Received
Published: 2026-10-05T01:16:28.923
Modified: 2026-10-05T01:16:28.923
Link: CVE-2026-105294
No data.
OpenCVE Enrichment
No data.
Weaknesses