CVE-2026-0776 is a local privilege escalation vulnerability in the Discord Client affecting the discord_rpc module. The flaw is caused by the application loading a file from an unsecured location, i.e., an uncontrolled search path element. A local attacker who already has the ability to run low-privileged code on the target system can exploit this behavior to cause the client to load attacker-controlled code or resources from an unsafe path, resulting in arbitrary code execution in the context of the target user. The issue was tracked by ZDI as ZDI-CAN-27057.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a small local proof-of-concept exploit for CVE-2026-0776, described as an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher script, a malicious JavaScript module placed under a bundled node_modules directory, and a README describing the issue. The main exploit logic is in CVE-2026-0776.py. It resolves the repository-local node_modules directory, copies it to C:\node_modules, verifies the presence of %LOCALAPPDATA%\Discord\Update.exe, and launches Discord via Update.exe with '--processStart Discord.exe'. After a short delay, it removes C:\node_modules. This indicates the exploit relies on Discord or a Node.js-based component loading a module from an unintended filesystem location during startup. The payload is in node_modules/utf-8-validate.js. When loaded, it imports child_process.exec and runs 'start cmd.exe /k echo CVE-2026-0776', which opens a command prompt as a visible marker of successful code execution. It then exports a benign-looking validate() function returning true, likely to preserve expected module behavior and avoid immediate failure if the application expects that module. There are no network callbacks, remote C2 endpoints, persistence mechanisms, credential theft routines, or destructive actions. The exploit is strictly local and file-system based. Its capability is to achieve arbitrary code execution in the context of the current user by planting a crafted module in C:\node_modules and triggering Discord startup. The code is operational but basic, with a hardcoded payload and cleanup routine, making it best classified as OPERATIONAL rather than weaponized.
This repository is a small standalone proof-of-concept exploit for CVE-2026-0776, described as an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher script, a malicious JavaScript module under node_modules, and a README describing the issue. The main exploit flow is implemented in CVE-2026-0776.py. It resolves the local node_modules directory bundled with the repo, copies it to C:\node_modules, verifies the presence of %LOCALAPPDATA%\Discord\Update.exe, and launches Discord via Update.exe --processStart Discord.exe. After a short delay, it removes the planted directory for cleanup. The payload module node_modules/utf-8-validate.js abuses Node.js module resolution behavior: when loaded by the vulnerable application, it uses child_process.exec to run 'start cmd.exe /k echo CVE-2026-0776', providing a benign visible indicator of code execution. This is a local privilege-equivalent code execution PoC rather than a remote exploit; it requires local filesystem access and a vulnerable Discord installation. The exploit is operational because it includes a working payload, but it is basic and hardcoded rather than highly customizable.
This repository is a small standalone local exploit PoC for CVE-2026-0776, described as an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher script (CVE-2026-0776.py), a malicious JavaScript module placed under node_modules/utf-8-validate.js, and a README describing the vulnerability and limitations. The main exploit flow is implemented in CVE-2026-0776.py. It resolves the local bundled node_modules directory, copies it to C:\node_modules, locates %LOCALAPPDATA%\Discord\Update.exe, and launches Discord using Update.exe --processStart Discord.exe. After a short delay, it removes C:\node_modules to clean up. This indicates the exploit abuses unsafe module resolution / search path behavior during Discord startup. The payload is in node_modules/utf-8-validate.js. When this module is loaded, it imports child_process.exec and runs 'start cmd.exe /k echo CVE-2026-0776', which visibly demonstrates arbitrary code execution. It then exports a benign-looking validate function, likely to satisfy expected module semantics and reduce the chance of immediate failure. There are no network callbacks, C2 endpoints, persistence mechanisms, credential theft routines, or destructive actions. The exploit is purely local and file-system based, requiring the attacker to run code on the target machine and have sufficient permissions to write to C:\node_modules. Overall, this is a real PoC exploit rather than a detector: it operationalizes local code execution via planted module search path hijacking against Discord Desktop Client version 1.0.9196 on Windows.
This repository is a small standalone local exploit PoC for CVE-2026-0776, described as an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher/exploit script, a malicious JavaScript module placed under a node_modules directory, and a README describing the issue. The main exploit logic is in CVE-2026-0776.py. It resolves the local bundled node_modules directory, copies it to C:\node_modules, verifies the presence of %LOCALAPPDATA%\Discord\Update.exe, and launches Discord using Update.exe --processStart Discord.exe. After a short delay, it removes C:\node_modules to clean up. This indicates the exploit abuses unsafe module resolution/search path behavior during Discord startup. The payload is in node_modules/utf-8-validate.js. When loaded, it imports child_process.exec and runs 'start cmd.exe /k echo CVE-2026-0776', which visibly demonstrates arbitrary code execution under the current user context. The module then exports a benign-looking validate() function so it can still satisfy expected application behavior. There are no network callbacks, C2 features, persistence, privilege escalation, or data theft capabilities. The exploit is purely local and file-system based, intended to prove code execution by planting a malicious dependency in a searched path. Because it includes a working payload but only a simple hardcoded demonstration command, the maturity is best classified as OPERATIONAL rather than WEAPONIZED.
This repository is a small local privilege-context code execution PoC for CVE-2026-0776, described as an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher/stager (CVE-2026-0776.py), a malicious JavaScript module placed under node_modules/utf-8-validate.js, and a README describing the issue. The main exploit flow is straightforward: the Python script resolves its bundled node_modules directory, copies it to C:\node_modules, locates %LOCALAPPDATA%\Discord\Update.exe, and launches Discord via Update.exe with --processStart Discord.exe. The intended effect is to abuse unsafe module resolution so Discord loads the attacker-controlled utf-8-validate.js from C:\node_modules. That JavaScript payload uses Node's child_process.exec to run 'start cmd.exe /k echo CVE-2026-0776', demonstrating arbitrary code execution in the user context. After a 10-second delay, the Python script removes C:\node_modules as cleanup. Capabilities are limited but clearly exploitative: staging a malicious module in a searched filesystem path, triggering the vulnerable application to load it, executing an arbitrary OS command, and cleaning up artifacts. There is no network communication, persistence, credential theft, or exfiltration logic. This is a local/file-based exploit rather than a remote exploit, and the included payload is a benign demonstration command rather than a full post-exploitation implant. The exploit is operational rather than just a detector because it actively attempts code execution on a target system. It is not part of a known exploit framework.
This repository is a small standalone local exploit PoC for CVE-2026-0776, an uncontrolled search path element issue in the Discord Desktop Client on Windows. The repo contains three files: a Python launcher script (CVE-2026-0776.py), a malicious JavaScript module placed under node_modules/utf-8-validate.js, and a README describing the issue. The main exploit flow is implemented in CVE-2026-0776.py. It resolves the local bundled node_modules directory, copies it to C:\node_modules, verifies the presence of %LOCALAPPDATA%\Discord\Update.exe, and launches Discord using Update.exe with --processStart Discord.exe. After a short delay, it removes C:\node_modules to clean up. This indicates the exploit abuses unsafe module resolution/search path behavior during Discord startup. The payload is in node_modules/utf-8-validate.js. When loaded, it imports child_process.exec and runs 'start cmd.exe /k echo CVE-2026-0776', demonstrating arbitrary code execution in the user context. It then exports a benign-looking validate() function returning true, likely to satisfy expected module semantics and avoid immediate failure. There are no network callbacks, C2 endpoints, persistence mechanisms, credential theft routines, or destructive actions. The exploit is purely local and file-system based. Its purpose is to demonstrate code execution by planting a crafted module in a searched path and triggering Discord to load it. Because it includes an actual executable payload but it is simple and hardcoded, the maturity is best classified as OPERATIONAL rather than just POC or weaponized.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.