Remote Code Execution Vulnerability in Hikka Telegram Userbot
CVE-2025-52571

9.7CRITICAL

Key Information:

Status
Vendor
CVE Published:
24 June 2025

What is CVE-2025-52571?

A serious vulnerability in the Hikka Telegram Userbot allows unauthenticated attackers to gain control over users' Telegram accounts and servers. All versions prior to 1.6.2, including several forks, are susceptible to this flaw, which has been addressed in the latest release. There are no known workarounds, making it imperative for users to upgrade to the patched version to ensure the security of their accounts.

Affected Version(s)

Hikka < 1.6.2

References

CVSS V3.1

Score:
9.7
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-52571 : Remote Code Execution Vulnerability in Hikka Telegram Userbot