Stored XSS in Telegram Desktop HTML exports

A bot could embed JavaScript in the label of an inline keyboard button. Telegram displayed the label as plain text, but vulnerable Telegram Desktop builds copied button.text.toUtf8() into exported HTML without passing it through SerializeString(). As a result, a <script> tag in the label executed when a participant opened the export.
Forwarded messages retained the button, so the bot did not need to be a member of the target group. Another user only had to forward the crafted message. A run of U+3164 characters made the malicious part of the label less visible in the client, and no additional click was needed once the export was opened.
The script could read messages and metadata rendered in the exported page, send them to an external server, or rewrite the page. It remained confined to that document and did not expose Telegram's server-side history.
Tracked as CVE-2026-94488, the bug was fixed in Beta 6.9.4 and Stable 7.0.1. HTML exports generated by affected builds remain unsafe even after the desktop client is updated.
Vulnerabilities
8.2
CVE-2026-94488
Vendors
Telegram
Products
Html Exports
Inline Keyboard Button
Telegram Desktop