OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94488

HIGH · CVSS 8.2 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Telegram Desktop versions prior to 6.9.4 are vulnerable to a cross-site scripting (XSS) flaw in the HTML exporter, specifically in the button.text.toUtf8 function. This vulnerability allows attackers to craft malicious payloads that can be triggered when a victim uses the HTML export feature, particularly if a message containing the exploit is forwarded into a group chat. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks, especially those that utilize HTML exports in their communications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94488
Severity
HIGH
CVSS
8.2
EPSS
0.14%

Original NVD Description

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).