HTML Injection Vulnerability in DiscordChatExporter by Tyrrrz
CVE-2026-54681
4.1MEDIUM
What is CVE-2026-54681?
DiscordChatExporter, a tool for saving Discord chat logs, contains an HTML injection vulnerability due to improper handling of emoji attributes in exports. The VisitEmojiAsync method fails to encode HTML entities for emoji names and codes, leading to potential script execution if a malformed export is opened. This issue affects all HTML exports regardless of markdown settings and is particularly concerning when offline input is manipulated or upstream validation rules are too permissive. The vulnerability has been addressed in version 2.47.2.
Affected Version(s)
DiscordChatExporter < 2.47.2
