HIGH
GramSearch
CVE published 2026-08-11
CVE-2026-73031
CVE-2026-73031 is a stored cross-site scripting vulnerability in telegram-search that allows remote attackers to execute arbitrary JavaScript in victims' browsers by sending crafted messages containing unsanitized HTML to a shared Telegram group. This vulnerability is caused by the highlightKeyword function in MessageList.vue passing raw message content directly to v-html without HTML escaping or sanitiza [truncated]