Telegram Desktop HTML export escaping fix
Security Patch Release
Summary
Hide ▲
Show ▼
Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6.9.4 beta and 7.0.1 stable, while older HTML exports created before the fix can still carry the script. Opening one of those files in a browser could expose chat content or let the page be rewritten.
Related Happenings
Telegram Desktop old HTML export mitigation
Advisory/Mitigation
H score30
First: 14.09.2026 20:58
Last: 14.09.2026 20:58
Sources 1
How related:
Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.
About this happening:
Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...
Telegram Desktop old HTML export mitigation
Advisory/MitigationHow related: Update Telegram Desktop to 7.0.1 or later, or to 6.9.4 or later on the beta channel.
About this happening: Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The res...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware Activity
H score14
First: 01.07.2026 00:02
Last: 01.07.2026 00:02
Sources 1
About this happening:
Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
Trojanized Pyrogram forks with hidden Telegram backdoor
Malware ActivityAbout this happening: Trojanized Pyrogram forks on PyPI now ship a hidden backdoor that gives attackers remote command execution and file access on compromised Telegram bot servers. The mal...
Timeline
-
14.09.2026 20:58 1 articles · 3h ago
Researchers report Telegram Desktop HTML export JavaScript injection flaw
Initial DisclosureExPatch researchers Denis Rostilov and Aleksander Rostilov reported that a bot message in Telegram Desktop could plant hidden JavaScript inside HTML chat exports when inline keyboard button text was written without escaping.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
14.09.2026 20:58 2 articles · 3h ago
Telegram Desktop 7.0.1 ships HTML export escaping fix
Mitigation Patch UpdateTelegram Desktop 7.0.1 stable added the missing escaping for inline keyboard button text in HTML exports, closing the path that let a bot message embed script in exported chats.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58
-
12.09.2026 03:00 1 articles · 2d ago
ExPatch publishes Telegram Desktop HTML export exploit analysis
Technical Analysis UpdateExPatch published a writeup showing that a hidden script in a Telegram Desktop HTML export could run in a browser, copy messages and metadata to an attacker-controlled server, or rewrite the exported page.
Show sources
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports — thehackernews.com — 14.09.2026 20:58