PT-2026-79427 · Unknown · Discordchatexporter
CVE-2026-54681
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
4.1
Medium
| Vector | AV:L/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
DiscordChatExporter versions prior to 2.47.2
Description
The
VisitEmojiAsync() function in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs fails to perform HTML entity encoding when interpolating emoji.Name into the alt attribute and emoji.Code into the title attribute. This flaw affects HTML exports regardless of the markdown configuration. While standard validation typically prevents attribute-breaking characters, tampered offline input or changes in upstream validation could allow an attacker to inject HTML attributes and execute malicious scripts when a user opens the exported file.Recommendations
Update to version 2.47.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Discordchatexporter