HTML Injection Vulnerability in DiscordChatExporter by Tyrrrz
CVE-2026-54681

4.1MEDIUM

Key Information:

Vendor

Tyrrrz

Vendor
CVE Published:
21 August 2026

What is CVE-2026-54681?

DiscordChatExporter, a tool for saving Discord chat logs, contains an HTML injection vulnerability due to improper handling of emoji attributes in exports. The VisitEmojiAsync method fails to encode HTML entities for emoji names and codes, leading to potential script execution if a malformed export is opened. This issue affects all HTML exports regardless of markdown settings and is particularly concerning when offline input is manipulated or upstream validation rules are too permissive. The vulnerability has been addressed in version 2.47.2.

Affected Version(s)

DiscordChatExporter < 2.47.2

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.