Vulnerabilities & PatchesEmerging1 src
CVE-2026-54682 - DiscordChatExporter: Stored XSS in HTML export when markdown formatting is disabled
CVE ID : CVE-2026-54682
Published : Aug. 21, 2026, 6:40 p. m.
• 30 minutes ago
Description : DiscordChatExporter saves Discord chat logs to a file. Prior to 2. 47. 2, HTML exports generated with markdown formatting disabled pass attacker-controlled content through FormatMarkdownAsync and FormatEmbedMarkdownAsync in DiscordChatExporter. Core/Exporting/MessageGroupTemplate. cshtml and render it without HTML entity encoding. The affected fields include message. Content, message. ForwardedMessage.
Content, message. ReferencedMessage. Content, embed. Title, embed. Description, field. Name, and field. Value. A Discord webhook or bot can store a script payload in these fields, and the payload executes when a user exports the channel with markdown formatting disabled and opens the resulting HTML, allowing the script to read the export or alter its displayed content.