Telegram Desktop through 2.1.13 allows a spoofed file type to bypass the Dangerous File Type Execution protection mechanism, as demonstrated by use of the chat window with a filename that lacks an extension.
{
"cpe": "cpe:2.3:a:telegram:telegram_desktop:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "2.1.13"
}
]
}
[
{
"target": {
"file": "Telegram/SourceFiles/core/version.h"
},
"deprecated": false,
"id": "CVE-2020-17448-f7e81173",
"signature_version": "v1",
"digest": {
"line_hashes": [
"319953548780886678756405202304630774357",
"228928258810351972415558832941811870001",
"157717428114421186897809694267172552622",
"217076276116021232503611570573011364623",
"38342476542662820831055528795007988962",
"109514707017027402583239583824590233658"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/telegramdesktop/tdesktop/commit/e5434ea4915a93eb90b4c75ae79cb571001f7e3b"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-17448.json"
"2026-07-08T20:30:36Z"