CVE-2026-48046

Summary

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.

Affected Software

VendorProductVersion RangeStatus
truelockmcstreambert< 2.5.0affected

Weaknesses

  • CWE-494: CWE-494: Download of Code Without Integrity Check

References