CVE-2025-52571: Hikariatama Hikka
Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.
Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workarounds are available.
Affected products
- Hikariatama Hikka: before 1.6.2 (fixed in 1.6.2)
Published 2025-06-24. Last modified 2026-06-17.