CVE-2020-17448: Telegram Desktop

High severity, CVSS 7.8. EPSS: 2.3% chance of exploitation in the next 30 days.

Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.

Affected products

  • Telegram Telegram Desktop: up to and including 2.1.13

Published 2020-08-11. Last modified 2026-06-17.