{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/telegram-search/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.7,"id":"CVE-2026-73031"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["telegram-search"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["telegram-search"],"content_html":"\u003cp\u003eCVE-2026-73031 identifies a critical stored cross-site scripting (XSS) vulnerability within the telegram-search application. The flaw originates in the MessageList.vue component, specifically within the \u003ccode\u003ehighlightKeyword\u003c/code\u003e function, which processes and renders message content using the Vue.js \u003ccode\u003ev-html\u003c/code\u003e directive without performing adequate HTML escaping or sanitization. This oversight permits an attacker to inject arbitrary HTML and JavaScript payloads into messages within a shared Telegram group. Because the application processes these messages for searching and viewing, the injected code is stored persistently and executes in the context of any user who views or performs a search operation that includes the malicious message. This is effectively a zero-click execution vector that poses a significant risk for session hijacking or unauthorized actions performed in the victim's browser session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to execute arbitrary JavaScript in the browsers of legitimate users. This can lead to the exfiltration of session cookies, sensitive user data, or unauthorized actions performed on behalf of the victim. Given the nature of stored XSS in search and message-viewing components, any user interacting with the compromised group or search results is vulnerable, potentially affecting the entire user base of the affected telegram-search deployment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize updating the telegram-search application to the latest version that implements proper HTML sanitization for the \u003ccode\u003ehighlightKeyword\u003c/code\u003e function. Audit the codebase to ensure all instances using the \u003ccode\u003ev-html\u003c/code\u003e directive are coupled with a robust sanitization library like DOMPurify before rendering user-supplied content. Implement a Content Security Policy (CSP) that restricts script execution to trusted sources to mitigate the impact of potential XSS vulnerabilities.\u003c/p\u003e\n","date_modified":"2026-08-11T21:51:09Z","date_published":"2026-08-11T21:51:09Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-73031/","summary":"A stored cross-site scripting (XSS) vulnerability (CVE-2026-73031) in telegram-search allows remote attackers to execute arbitrary JavaScript by injecting unsanitized HTML into shared Telegram messages.","title":"Stored XSS in telegram-search via MessageList.vue","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-73031/"}],"language":"en","title":"CraftedSignal Threat Feed - Telegram-Search","version":"https://jsonfeed.org/version/1.1"}