CVE-2026-48056

Summary

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.

Affected Software

VendorProductVersion RangeStatus
truelockmcstreambert< 2.5.0affected

Weaknesses

  • CWE-20: CWE-20: Improper Input Validation
  • CWE-749: CWE-749: Exposed Dangerous Method or Function

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: poc
    • Automatable: yes
    • Technical Impact: total

Additional References

References