No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 06 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Legcord
Legcord legcord |
|
| Vendors & Products |
Legcord
Legcord legcord |
Mon, 05 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 05 Oct 2026 01:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy. | |
| Title | Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig | |
| Weaknesses | CWE-15 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-05T20:28:31.628Z
Reserved: 2026-10-05T00:19:08.246Z
Link: CVE-2026-105294
Updated: 2026-10-05T19:18:29.442Z
Status : Deferred
Published: 2026-10-05T01:16:28.923
Modified: 2026-10-06T16:08:43.180
Link: CVE-2026-105294
No data.
OpenCVE Enrichment
Updated: 2026-10-06T21:09:46Z