CVE-2026-105294 | Legcord up to 1.3.0 Configuration Injection setConfig additionalArguments cross site scripting

SecurityVulns

A vulnerability classified as problematic was found in Legcord up to 1.3.0. This affects the function setConfig of the component Configuration Injection. Executing a manipulation of the argument additionalArguments can lead to cross site scripting.

This vulnerability is handled as CVE-2026-105294. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More