CVE-2026-48056
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Summary
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| truelockmc | streambert | < 2.5.0 | affected |
Weaknesses
- CWE-20: CWE-20: Improper Input Validation
- CWE-749: CWE-749: Exposed Dangerous Method or Function
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: total
Additional References
References
- https://github.com/truelockmc/streambert/security/advisories/GHSA-x267-77m6-qjc9
- https://github.com/truelockmc/streambert/releases/tag/2.5.0
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.