Hi,
The following vulnerability was published for telegram-desktop.
CVE-2026-94488[0]:
| Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The
| first fixed stable version is 7.0.1.) This occurs in
| button.text.toUtf8 in export_output_html.cpp. Exploitation cannot
| occur unless HTML export was used by a victim. However, the exploit
| payload can be exported if a message were forwarded into a group by
| a member (it is not necessary for the message author to be a member
| of a group).
https://expatch.com/writeups/telegram-html-export-xss.html
https://github.com/telegramdesktop/tdesktop/commit/8457d13aa795fadf99c955d2a04f00ebc3c59df9 (v6.9.4)
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-94488
https://www.cve.org/CVERecord?id=CVE-2026-94488
Please adjust the affected versions in the BTS as needed.