CVE-2025-52571: Hikariatama Hikka

Critical severity, CVSS 9.6. EPSS: 0.3% chance of exploitation in the next 30 days.

Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workarounds are available.

Affected products

Published 2025-06-24. Last modified 2026-06-17.