Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 07 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Telegram Desktop before 7.2.9 contains an IPC record-separator injection vulnerability in Core::Sandbox that allows remote attackers to inject OPEN: records via crafted tg:// links containing unescaped semicolons. Attackers can reach the interpret: scheme handler to upload local files, including tdata session keys, to an attacker channel, enabling account takeover. | |
| Title | Telegram Desktop before 7.2.9 IPC Record Injection File Exfiltration via interpret: Scheme | |
| First Time appeared |
Telegram
Telegram telegram Desktop |
|
| Weaknesses | CWE-143 | |
| CPEs | cpe:2.3:a:telegram:telegram_desktop:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Telegram
Telegram telegram Desktop |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-07T17:04:52.514Z
Reserved: 2026-10-07T13:01:39.479Z
Link: CVE-2026-107181
Updated: 2026-10-07T16:09:52.538Z
Status : Awaiting Analysis
Published: 2026-10-07T14:17:08.807
Modified: 2026-10-07T17:16:53.520
Link: CVE-2026-107181
No data.
OpenCVE Enrichment
Updated: 2026-10-07T15:45:06Z
-
CWE-143
Improper Neutralization of Record Delimiters