#1150329 telegram-desktop: CVE-2026-94488

Package:
src:telegram-desktop
Source:
src:telegram-desktop
Submitter:
Moritz Mühlenhoff
Date:
2026-10-08 18:45:04 UTC
Severity:
normal
Tags:
#1150329#5
Date:
2026-10-08 17:31:26 UTC
From:
To:
Hi,

The following vulnerability was published for telegram-desktop.

CVE-2026-94488[0]:
| Telegram Desktop before 6.9.4 allows XSS in the HTML exporter. (The
| first fixed stable version is 7.0.1.) This occurs in
| button.text.toUtf8 in export_output_html.cpp. Exploitation cannot
| occur unless HTML export was used by a victim. However, the exploit
| payload can be exported if a message were forwarded into a group by
| a member (it is not necessary for the message author to be a member
| of a group).

https://expatch.com/writeups/telegram-html-export-xss.html
https://github.com/telegramdesktop/tdesktop/commit/8457d13aa795fadf99c955d2a04f00ebc3c59df9 (v6.9.4)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-94488
https://www.cve.org/CVERecord?id=CVE-2026-94488

Please adjust the affected versions in the BTS as needed.