Advisory · CVE-2026-105294
Legcord config injection can force all traffic through an attacker proxy
Legcord 1.1.0 through 1.3.0 lets script in the Discord page write any config key, so an attacker can persistently add Chromium proxy flags and route all client traffic through an interception proxy.
- Vendor
- Legcord
- Product
- Legcord
- Identifier / CWE
- CVE-2026-105294
CWE-15 - Action timing
- Immediate
Explain it like I’m five
Legcord lets the Discord page tweak its settings, and never checks whether a setting is on the approved list. An attacker can slip in a setting that says 'send everything through my computer first' and turn off the warnings that would flag it.
- 01Get script in the page
An attacker gets JavaScript running in the Discord page origin inside Legcord, for example through a Discord-side script injection.
- 02Reach the settings bridge
That script uses the window.legcord settings.setConfig bridge, which writes configuration keys without restriction.
- 03Inject Chromium flags
The attacker sets additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches.
- 04Restart and intercept
After a restart, Legcord routes all traffic through the attacker's interception proxy and no longer flags bad certificates.
- 05Steal from the stream
With the client trusting anything, the attacker can read and modify tokens, credentials, and messages in flight.
What happened
Legcord 1.1.0 through 1.3.0 exposes a settings bridge (window.legcord settings.setConfig) to scripts running in the Discord page origin, and that bridge writes arbitrary configuration keys. Script in the page — for example through a Discord-side script injection — can set the additionalArguments config value, which Legcord passes through to Chromium at launch. An attacker can persistently add --proxy-server and --ignore-certificate-errors, so every restart routes all Legcord traffic through an interception proxy while the client stops flagging invalid certificates. The combination turns a page-level foothold into full traffic interception, rated critical at CVSS 9.1.
What to do
- Inventory where Legcord is installed, including personal and shared machines.
- Track the open Legcord issue #1163 and the project’s releases for a fixed build; no patched release has been published yet.
- Inspect Legcord’s stored configuration for unexpected
additionalArgumentsentries, especially any--proxy-servervalues pointing outside your network. - If any machine shows signs of exposure, rotate Discord tokens, session credentials, and any passwords used while Legcord ran with injected flags.
- Until a fix lands, avoid entering sensitive credentials in Legcord and treat its traffic as untrustworthy on shared or unmanaged networks.
Management note
This is a persistent interception primitive: the attacker only needs one successful page-level script execution to redirect all future traffic through their proxy. Unlike a transient MITM, it survives restarts by design. Until Legcord restricts the settings bridge, anyone managing endpoints with the client installed should check the stored config as part of incident review, not just network traffic.