{"id":"CVE-2025-52571","summary":"Hikka vulnerable to RCE through edits in a channel","details":"Hikka is a Telegram userbot. A vulnerability affects all users of versions below 1.6.2, including most of the forks. It allows an unauthenticated attacker to gain access to Telegram account of a victim, as well as full access to the server. The issue is patched in version 1.6.2. No known workarounds are available.","aliases":["GHSA-vwpq-wm8w-44wf"],"modified":"2026-08-12T03:51:30.037196304Z","published":"2025-06-24T20:07:24.328Z","database_specific":{"cwe_ids":["CWE-287"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52571.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"fixed":"1.6.2"}]}],"cna_assigner":"GitHub_M"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52571.json"},{"type":"ADVISORY","url":"https://github.com/hikariatama/Hikka/security/advisories/GHSA-vwpq-wm8w-44wf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52571"},{"type":"FIX","url":"https://github.com/hikariatama/Hikka/commit/9a0e4b1b387ef828c345c43d990421d5afcff5f6"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hikariatama/hikka","events":[{"introduced":"0"},{"fixed":"9a0e4b1b387ef828c345c43d990421d5afcff5f6"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v1.2.7","v1.1.28","v1.1.26","v1.1.24","v1.1.21","v1.1.20","v1.1.19","v1.1.18"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52571.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H"}]}