PatchSiren

GramSearch CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH GramSearch CVE published 2026-08-11

CVE-2026-73031

CVE-2026-73031 is a stored cross-site scripting vulnerability in telegram-search that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. This vulnerability is caused by the highlightKeyword function in MessageList.vue passing raw message content directly to v-html without HTML escaping or sanitiza [truncated]