Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gramsearch
Gramsearch telegram-search |
|
| Vendors & Products |
Gramsearch
Gramsearch telegram-search |
Tue, 11 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. The highlightKeyword function in MessageList.vue passes raw message content directly to v-html without HTML escaping or sanitization, enabling stored, cross-user, zero-click execution of injected payloads such as image onerror handlers when victims browse or search messages. | |
| Title | telegram-search Stored XSS via v-html in MessageList.vue | |
| Weaknesses | CWE-79 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T20:04:38.629Z
Reserved: 2026-08-10T18:48:59.022Z
Link: CVE-2026-73031
Updated: 2026-08-14T20:04:32.847Z
Status : Received
Published: 2026-08-11T20:18:46.173
Modified: 2026-08-14T20:16:57.283
Link: CVE-2026-73031
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:49:36Z
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')