CVE-2026-94488

LOWCVSS 8.3 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp. Exploitation cannot occur unless HTML export was used by a victim. However, the exploit payload can be exported if a message were forwarded into a group by a member (it is not necessary for the message author to be a member of a group).

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 3 mentions on most recent observed day (2026-09-22)
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-09-21: 1Mentions · 2026-09-22: 309-2109-22
Referenced assets4 URLs
Full discourse4 posts
  • Ryx@PadhiyarRushi

    Telegram Desktop HTML exporter XSS!!! CVE-2026-94488: XSS in the HTML exporter path (button.text.toUtf8 in export_output_html.cpp) affecting builds before 6.9.4 (fixed stable path noted as 7.0.1). Client-side, but still a clean parser bug class. https://www.thehackerwire.com/vulnerability/CVE-2026-94488/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #AppSec #XSS

    10011139
    880 followersView on X
  • CVE@CVEnew

    CVE-2026-94488 Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The first fixed stable version is 7.0.1.) This occurs in button.text.toUtf8 in export_output_html.cpp.… https://www.cve.org/CVERecord?id=CVE-2026-94488

    00001678
    58.1K followersView on X
  • Hephaestvs@Vulcanux_

    csirt_it: ‼️ #PoC #Telegram: Disponibile Proof of Concept (PoC) per la vulnerabilità identificata dalla CVE-2026-94488 in Telegram Desktop Rischio: 🔴 Tipologia: 🔸 Security Feature Bypass 🔗 https://www.acn.gov.it/portale/w/telegram-desktop-poc-pubblica-per-lo-sfruttamento-della-cve-2026-94488 ⚠️ Importante mantenere aggiornati… https://t.co/tyARGhIC1s

    0000037
    636 followersView on X
  • VulnTracker@vuln_tracker

    A forwarded Telegram message can carry a hidden XSS payload into your HTML export (CVSS 8.2). CVE-2026-94488 sits in Telegram Desktop's HTML exporter. The exploit only fires when a victim exports a chat to HTML, but the payload can ride in through a forwarded message, no group membership required. Proof-of-concept exploit code is already public. Fixed in Telegram Desktop 7.0.1. Update now. Details: http://vulntracker.io/cves/CVE-2026-94488 #Telegram #CVE #XSS #InfoSec #CyberSecurity

    00000119
    759 followersView on X

Explore more