๐Ÿ” CVE Alert

CVE-2026-94488

HIGH 8.2
CVSS Score
8.2
EPSS Score
0.0%
EPSS Percentile
0th

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).

CWE CWE-79
Vendor telegram
Product telegram desktop
Published Sep 21, 2026
Last Updated Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for telegram telegram desktop

Be the first to know when new high vulnerabilities affecting telegram telegram desktop are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

Telegram / Telegram Desktop
4.15.1 < 6.9.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/telegramdesktop/tdesktop/commit/8457d13aa795fadf99c955d2a04f00ebc3c59df9 github.com: https://github.com/telegramdesktop/tdesktop/commit/52c779bffa8dde3c5c09826add2607328fae0924 github.com: https://github.com/telegramdesktop/tdesktop/releases/tag/v6.9.4 github.com: https://github.com/telegramdesktop/tdesktop/blob/v6.9.3/Telegram/SourceFiles/export/output/export_output_html.cpp expatch.com: https://expatch.com/writeups/telegram-html-export-xss.html thehackernews.com: https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html