CVE-2026-94488 | Telegram Desktop up to 6.9.3 HTML Export export_output_html.cpp button.text.toUtf8 HTML injection

SecurityVulns

A vulnerability, which was classified as problematic, was found in Telegram Desktop up to 6.9.3. This impacts the function button.text.toUtf8 of the file export_output_html.cpp of the component HTML Export. The manipulation results in HTML injection.

This vulnerability is identified as CVE-2026-94488. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.VulDB Recent EntriesRead More