How to Run the Discord RCE Exploit with run.ps1: A Complete Guide
To execute the Discord Activity stock-client RCE exploit with run.ps1, validate your Discord executable hash, provide a public HTTPS origin via the -PublicOrigin parameter, and let the PowerShell launcher coordinate the Node.js server, monitor the exploit state, and automatically restore Discord settings upon completion.
The discord-activity-stock-client-rce-poc proof-of-concept in the bikini/exploitarium repository demonstrates a full chain from V8 memory primitives to native code execution via Electron IPC. The run.ps1 PowerShell script serves as the central orchestrator, handling environment preparation, server lifecycle management, and post-exploit cleanup. This guide walks through every phase of running the exploit safely on a controlled Windows system.
Prerequisites and Environment Setup
Before invoking run.ps1, your environment must meet strict version and configuration requirements. The exploit targets specific Discord internals and will fail against incompatible builds.
- Operating System: Windows 11 x64 with PowerShell 5.1 or later.
- Discord Version: Exactly build 1.0.9245 running as the stock client (not Canary or PTB).
- Dependencies: Node.js installed globally, a cloudflared or equivalent HTTPS tunnel, and a Discord developer application with Activities enabled.
- Network: A running HTTPS tunnel forwarding all paths to your local machine, typically via
cloudflared tunnel --url http://127.0.0.1:3077.
The repository README at discord-activity-stock-client-rce-poc/README.md (lines 35-44) details the full requirements checklist and tunnel configuration steps.
How run.ps1 Orchestrates the Exploit Chain
The run.ps1 launcher operates in distinct phases: validation, injection, execution, monitoring, and recovery. Each phase correlates to specific line ranges in the script.
Environment Variable Injection
On lines 62-76 of run.ps1, the launcher prepares the runtime environment by injecting critical variables that drive server behavior. These variables include the listening port, public origin URL, and RCE-specific configuration candidates. The script then spawns the Node.js server process on line 78 with these variables in scope.
# Lines 62-76 prepare environment variables
# Line 78 spawns: node server.js
Discord Executable Validation
Before modifying any settings, run.ps1 verifies the integrity of the target Discord executable against a known hash. Lines 10-30 perform this validation to ensure the exploit chain matches the expected binary layout. If validation fails, the script exits immediately to prevent undefined behavior against mismatched builds.
The script also creates a backup of settings.json during this phase, storing it for later restoration by the Restore-Settings function defined on lines 25-31.
Server Initialization and Health Checks
After spawning the server process, run.ps1 enters a polling loop on lines 80-86, repeatedly requesting http://127.0.0.1:<port>/health until the endpoint responds. This ensures the Activity payload server is ready before the user proceeds.
Once healthy, the script prints user instructions on lines 88-90, prompting you to launch the configured Activity in Discord and wait for the "lease-granted" message.
Executing the RCE Proof-of-Concept
With the environment validated and server running, you trigger the actual exploit through Discord's Activity interface.
Configuring the Discord Activity
First, create a Discord developer application and enable the Activity feature. Map the root URL (/) to your HTTPS tunnel endpoint, then launch the Activity from within Discord. The README (lines 48-64) provides detailed steps for Activity configuration, including the HTTPS tunnel mapping requirements.
Running run.ps1 with Parameters
Execute the launcher from the repository root, passing your public tunnel origin:
.\run.ps1 -PublicOrigin "https://<PUBLIC_TUNNEL_HOST>"
The script accepts additional parameters for debugging and timeout control, but -PublicOrigin is mandatory. The launcher immediately displays the server status and waits for your interaction with the Discord client.
Monitoring and Verification
After you click Run Calculator proof in the Activity UI, run.ps1 monitors the exploit progress via the /rce/state endpoint (lines 94-112). The script polls for two specific flags: nativeExitSuccess and recoveryRelaunchRequested. When both return true and the launcher detects the Calculator process (calc.exe) via process enumeration, it considers the exploit successful.
The monitoring loop also tracks process IDs to confirm that CreateProcessW executed within the Discord binary context.
Recovery and Cleanup Mechanisms
Upon successful native execution, run.ps1 automatically invokes Restore-Settings (lines 25-31) to revert settings.json to its pre-exploit state. This ensures Discord returns to normal operation without manual intervention.
The cleanup block on lines 118-127 handles final environment restoration, Node process termination, and exit code management. If the exploit times out without triggering nativeExitSuccess, the script exits with status code 1, enabling programmatic failure detection:
.\run.ps1 -PublicOrigin "https://example.com"
if ($LASTEXITCODE -ne 0) {
Write-Error "Exploit failed or timed out"
}
Summary
- Validation Phase:
run.ps1checks Discord executable hashes and backs upsettings.jsonbefore any modifications. - Orchestration: The script injects environment variables, starts
server.js, and performs health checks at/health. - Execution: Users launch the Activity in Discord, trigger the proof via Run Calculator proof, and the V8 primitive chain executes through to
CreateProcessW. - Monitoring: The launcher polls
/rce/statefornativeExitSuccessand process creation events. - Cleanup: Automatic restoration of Discord settings and environment variables occurs regardless of exploit success or failure.
Frequently Asked Questions
What specific Discord version does the run.ps1 exploit target?
The run.ps1 launcher and the associated proof-of-concept specifically target Discord build 1.0.9245. The script validates the executable hash on lines 10-30 to ensure binary compatibility with the V8 memory primitive and IPC bridge offsets used in the exploit chain.
How does run.ps1 verify the exploit succeeded?
The launcher monitors the /rce/state endpoint for boolean flags nativeExitSuccess and recoveryRelaunchRequested while simultaneously polling for the Calculator process. When both flags return true and calc.exe appears in the process list, run.ps1 confirms successful native code execution and triggers settings restoration.
Can I run the Discord RCE exploit without PowerShell?
While server.js can technically run standalone with manually set environment variables, run.ps1 automates critical safety steps including executable validation, settings backup, and automatic recovery. Running without the PowerShell launcher risks leaving Discord in a modified state and requires manual cleanup of environment variables and settings.json.
What happens if the exploit fails or times out?
If the monitoring loop on lines 94-112 does not detect success within the timeout window, run.ps1 executes the cleanup block on lines 118-127. This restores original environment variables, terminates the Node server, and exits with status code 1. The settings.json backup is restored to ensure Discord remains functional regardless of exploit outcome.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →