CVE-2026-105294

CVE-2026-105294 published: Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to p...

View full NVD advisory → ← Back to CVE watch