Advisory · CVE-2026-105293
Legcord themes can be abused to run executables and delete directories
Legcord 1.1.0 through 1.3.0 fails to validate theme IDs in its theme IPC handlers, letting script in the Discord page escape the themes directory to launch executables, delete directories, and write files.
- Vendor
- Legcord
- Product
- Legcord
- Identifier / CWE
- CVE-2026-105293
CWE-22 - Action timing
- Immediate
Explain it like I’m five
Legcord keeps its themes in a locked box and hands out keys labeled with theme names. It never checks whether the name on the key matches a real theme, so a tricked key can open any drawer in the house, including ones that run programs or empty whole folders.
- 01Get script in the page
An attacker gets JavaScript running in the Discord page origin inside Legcord, for example through a Discord-side script injection.
- 02Call the theme bridge
That script calls Legcord's theme IPC handlers (themes.folder, themes.uninstall, themes.install) with a theme ID it controls.
- 03ID is not validated
The handlers use the theme ID to build a filesystem path without checking that it stays inside the themes directory.
- 04Path escapes the box
A crafted ID like a directory-traversal sequence resolves to a path outside the themes directory.
- 05System-wide impact
The attacker can launch local executables, recursively delete directories, or write files to attacker-chosen locations.
What happened
Legcord, the open-source Discord desktop client, exposes theme-management IPC handlers to scripts running in the Discord page origin. In releases 1.1.0 through 1.3.0, those handlers (themes.folder, themes.uninstall, themes.install) accept a theme ID and join it into a filesystem path without validating that the ID stays within the themes directory. Script running in the page — for example through a Discord-side script injection — can supply a traversal sequence and operate on arbitrary paths: launching local executables, recursively deleting directories, and writing files outside the themes folder. The flaw is rated critical at CVSS 9.2.
What to do
- Inventory where Legcord is installed, including personal and shared machines.
- Track the open Legcord issue #1163 and the project’s releases for a fixed build; no patched release has been published yet.
- Avoid installing third-party themes or plugins from untrusted sources until the fix lands, since theme handling is the exposed surface.
- Do not run Legcord in environments where script in the page could be leveraged for lateral file operations (shared workstations, jump boxes).
- If a machine may have been exposed through a malicious theme or script, review the filesystem and process history for unexpected executables or deleted directories before returning it to service.
Management note
This is a critical flaw in the IPC boundary of a desktop app, chainable from page-level script execution to local code execution and destructive file operations. The real risk is not themes themselves but any vector that puts attacker script inside the Legcord page. Until the project ships a fix, treat Legcord on managed endpoints as an app with an unpatched path from script to system.