{"id":"CVE-2026-105294","summary":"Legcord 1.1.0 through 1.3.0 Chromium Switch Injection via settings.setConfig","details":"Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.","modified":"2026-10-06T02:47:21.020105326Z","published":"2026-10-05T00:44:19.284Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-15"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105294.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105294.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-105294"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/legcord-1.1.0-through-1.3.0-chromium-switch-injection-via-settings-setconfig"},{"type":"REPORT","url":"https://github.com/Legcord/Legcord/issues/1163"},{"type":"PACKAGE","url":"https://github.com/Legcord/Legcord"},{"type":"ARTICLE","url":"https://github.com/Legcord/Legcord/blob/v1.3.0/src/discord/ipc.ts#L296-L299"},{"type":"ARTICLE","url":"https://github.com/Legcord/Legcord/blob/v1.3.0/src/main.ts#L277-L307"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/legcord/legcord","events":[{"introduced":"07451f0d7e110cf6d31d0e32abedcefcff256d78"},{"fixed":"c8d91f61296019bb0c45f375535de8c93cf26ee1"}],"database_specific":{"source":["AFFECTED_FIELD","DESCRIPTION"],"extracted_events":[{"introduced":"1.1.0"},{"last_affected":"1.3.0"},{"fixed":"1.3.0"}]}}],"versions":["v1.2.4","v1.2.3","v1.2.2","v1.2.1","v1.2.0","v1.1.5","v1.1.3","v1.1.2","v1.1.1","v1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105294.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"}]}