Cross-Site Scripting Vulnerability in DiscordChatExporter by Tyrrrz
CVE-2026-54682

8.2HIGH

Key Information:

Vendor

Tyrrrz

Vendor
CVE Published:
21 August 2026

What is CVE-2026-54682?

DiscordChatExporter has a vulnerability where it allows the export of chat logs without adequately encoding user-generated content when markdown formatting is disabled. This oversight enables attackers to inject scripts through various message fields, which are executed when an HTML file is opened by the user. The impacted fields can include message content and embed descriptions, exposing users to potential data leakage or content manipulation when channel exports are performed. This vulnerability was addressed in version 2.47.2.

Affected Version(s)

DiscordChatExporter < 2.47.2

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.