Telegram Desktop HTML export stored XSS went unnoticed for 2.5 years
ExPatch researchers found a stored XSS in Telegram Desktop's HTML chat export: inline keyboard button text was not escaped. Telegram patched it in July 2026, but no CVE was assigned and the vulnerable code shipped in stable releases for about two years and four months.
- Flaw in export_output_html.cpp: button text skipped SerializeString() escaping
- Fix is commit 8457d13a, adding a single SerializeString() call
- Rated CVSS 3.1 8.2 (High); no CVE assigned and no dedicated advisory
- Payload survives forwarding and fires when the exported HTML is opened
Read next
Security