CyberRota Analysis
AI-GeneratedTelegram Desktop versions prior to 6.9.4 are vulnerable to a cross-site scripting (XSS) flaw in the HTML exporter, specifically in the button.text.toUtf8 function. This vulnerability allows attackers to craft malicious payloads that can be triggered when a victim uses the HTML export feature, particularly if a message containing the exploit is forwarded into a group chat. Organizations using affected versions should prioritize patching to mitigate potential exploitation risks, especially those that utilize HTML exports in their communications.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).