CVE-2026-94488
Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).
- Published Sep 21, 2026
- CVSS 8.3 high
- 0.2% chance of exploitation in the next 30 days (EPSS)
- A fix is available