CVE-2026-105293

CVE-2026-105293 published: Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the Discord page to escape the themes directory via unvalidated theme ids. Attackers running script in the Discord origin, such as through XSS, c...

View full NVD advisory → ← Back to CVE watch