Executive brief
DiscordChatExporter is a tool that exports Discord chat conversations to HTML files for archival and sharing. When exporting chats containing custom emojis, the application fails to properly encode emoji names and codes in HTML attributes, allowing attackers to inject malicious script tags. An attacker who can tamper with emoji metadata (through offline input, upstream relaxation, or future changes) can execute arbitrary JavaScript when a user opens the exported HTML file.
Technical details
The vulnerability is an HTML attribute injection flaw in the VisitEmojiAsync method of HtmlMarkdownVisitor.cs. The emoji.Name and emoji.Code values are interpolated directly into the alt and title HTML attributes without entity encoding. This allows attribute-breaking characters to be injected, enabling script execution in the browser when the exported HTML is opened. The attack requires the attacker to control emoji metadata (either through Discord's emoji validation bypass, offline tampering, or changes to upstream validation rules). The vulnerability was fixed in version 2.47.2 by implementing proper HTML entity encoding for these attributes.
Affected products
- Tyrrrz DiscordChatExporter prior to 2.47.2
Timeline
- 2026-08-21: disclosed
- 2026-06-04: patched: Fix merged in commit f4d1e63