Act nowDisclosed

Advisory · CVE-2026-105294

Legcord config injection can force all traffic through an attacker proxy

Legcord 1.1.0 through 1.3.0 lets script in the Discord page write any config key, so an attacker can persistently add Chromium proxy flags and route all client traffic through an interception proxy.

Vendor
Legcord
Product
Legcord
Identifier / CWE
CVE-2026-105294
CWE-15
Action timing
Immediate
ELI5

Explain it like I’m five

Legcord lets the Discord page tweak its settings, and never checks whether a setting is on the approved list. An attacker can slip in a setting that says 'send everything through my computer first' and turn off the warnings that would flag it.

SIMPLIFIED_ATTACK_PATH05 STEPS
  1. 01Get script in the page

    An attacker gets JavaScript running in the Discord page origin inside Legcord, for example through a Discord-side script injection.

  2. 02Reach the settings bridge

    That script uses the window.legcord settings.setConfig bridge, which writes configuration keys without restriction.

  3. 03Inject Chromium flags

    The attacker sets additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches.

  4. 04Restart and intercept

    After a restart, Legcord routes all traffic through the attacker's interception proxy and no longer flags bad certificates.

  5. 05Steal from the stream

    With the client trusting anything, the attacker can read and modify tokens, credentials, and messages in flight.

What happened

Legcord 1.1.0 through 1.3.0 exposes a settings bridge (window.legcord settings.setConfig) to scripts running in the Discord page origin, and that bridge writes arbitrary configuration keys. Script in the page — for example through a Discord-side script injection — can set the additionalArguments config value, which Legcord passes through to Chromium at launch. An attacker can persistently add --proxy-server and --ignore-certificate-errors, so every restart routes all Legcord traffic through an interception proxy while the client stops flagging invalid certificates. The combination turns a page-level foothold into full traffic interception, rated critical at CVSS 9.1.

What to do

  1. Inventory where Legcord is installed, including personal and shared machines.
  2. Track the open Legcord issue #1163 and the project’s releases for a fixed build; no patched release has been published yet.
  3. Inspect Legcord’s stored configuration for unexpected additionalArguments entries, especially any --proxy-server values pointing outside your network.
  4. If any machine shows signs of exposure, rotate Discord tokens, session credentials, and any passwords used while Legcord ran with injected flags.
  5. Until a fix lands, avoid entering sensitive credentials in Legcord and treat its traffic as untrustworthy on shared or unmanaged networks.

Management note

This is a persistent interception primitive: the attacker only needs one successful page-level script execution to redirect all future traffic through their proxy. Unlike a transient MITM, it survives restarts by design. Until Legcord restricts the settings bridge, anyone managing endpoints with the client installed should check the stored config as part of incident review, not just network traffic.