Index
Search
Search the public record. Drafts and scheduled notes are not included.
research
Telegram Desktop one-click file theft is CVE-2026-107181
A researcher write-up shows how one click on a crafted external link could make Telegram Desktop before 7.2.9 send local files, including session data, to an attacker chat. CVSS 4.0 8.6 (VulnCheck). Fixed in 7.2.9 without a vendor advisory. Public PoC write-up exists. Not in CISA KEV; no known exploitation.
Published 2h ago
CVE-2026-107181
Telegram Desktop IPC record injection leading to local file exfiltration
Info disclosure
Published 2d ago
news
Goose recipe command execution is CVE-2026-85623
VulnCheck published CVE-2026-85623 / GHSA-rh2p-fw5h-rc3m for Goose: recipe stdio extensions and retry checks can run shell commands the unicode recipe scan does not inspect. CVSS 3.1 8.8. Goose 1.52.0 ships a Desktop consent-before-session fix. A public PoC exists. Not in CISA KEV.
Published 3d ago
CVE-2026-85623
Goose recipe stdio extensions run commands without scan coverage
RCE
Published 4 Sept 2026