CVE-2026-94488: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Telegram Telegram Desktop
CVE-2026-94488 is a high-severity cross-site scripting (XSS) vulnerability in Telegram Desktop versions from 4.15.1 up to but not including 6.9.4. The flaw exists in the HTML exporter component, specifically in the button.text.toUtf8 function within export_output_html.cpp. Exploitation requires the victim to use the HTML export feature, and the malicious payload can be exported if a message is forwarded into a group by any member, regardless of the original message author’s group membership. The first fixed stable version is 7.0.1.
AI Analysis
Technical Summary
Telegram Desktop before version 6.9.4 contains an improper neutralization of input vulnerability (CWE-79) in its HTML exporter. The vulnerability arises in the button.text.toUtf8 function in export_output_html.cpp, allowing an attacker to craft a malicious payload that triggers cross-site scripting when HTML export is used. Exploitation requires the victim to export HTML content, and the payload can be introduced by forwarding a message into a group by any member. The issue is fixed starting with Telegram Desktop 7.0.1.
Potential Impact
Successful exploitation of this vulnerability can lead to high-impact cross-site scripting attacks when a user exports HTML content using the vulnerable Telegram Desktop versions. This could allow execution of arbitrary scripts in the context of the exported HTML, potentially leading to information disclosure or other client-side impacts. However, exploitation requires user interaction with the HTML export feature, limiting the attack surface.
Mitigation Recommendations
Users should upgrade Telegram Desktop to version 7.0.1 or later, where this vulnerability is fixed. Since this is a client-side vulnerability affecting the HTML export feature, avoiding use of the HTML export function in vulnerable versions can mitigate risk until an upgrade is applied.
CVE-2026-94488: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Telegram Telegram Desktop
Description
CVE-2026-94488 is a high-severity cross-site scripting (XSS) vulnerability in Telegram Desktop versions from 4.15.1 up to but not including 6.9.4. The flaw exists in the HTML exporter component, specifically in the button.text.toUtf8 function within export_output_html.cpp. Exploitation requires the victim to use the HTML export feature, and the malicious payload can be exported if a message is forwarded into a group by any member, regardless of the original message author’s group membership. The first fixed stable version is 7.0.1.
CVSS v4.0
Score 8.3high
Affected software
Telegram
Telegram Desktop
pkg:github/Telegram DesktopRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Telegram Desktop before version 6.9.4 contains an improper neutralization of input vulnerability (CWE-79) in its HTML exporter. The vulnerability arises in the button.text.toUtf8 function in export_output_html.cpp, allowing an attacker to craft a malicious payload that triggers cross-site scripting when HTML export is used. Exploitation requires the victim to export HTML content, and the payload can be introduced by forwarding a message into a group by any member. The issue is fixed starting with Telegram Desktop 7.0.1.
Potential Impact
Successful exploitation of this vulnerability can lead to high-impact cross-site scripting attacks when a user exports HTML content using the vulnerable Telegram Desktop versions. This could allow execution of arbitrary scripts in the context of the exported HTML, potentially leading to information disclosure or other client-side impacts. However, exploitation requires user interaction with the HTML export feature, limiting the attack surface.
Mitigation Recommendations
Users should upgrade Telegram Desktop to version 7.0.1 or later, where this vulnerability is fixed. Since this is a client-side vulnerability affecting the HTML export feature, avoiding use of the HTML export function in vulnerable versions can mitigate risk until an upgrade is applied.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-09-21T17:29:01.000Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab1713055bf5e2cf54534f4
Added to database: 09/21/2026, 18:02:24 UTC
Last enriched: 09/21/2026, 18:16:42 UTC
Last updated: 09/21/2026, 19:16:13 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.