PT-2026-50120 · Unknown · Streambert

·

CVE-2026-48055

·

Published

2026-06-16

·

Updated

2026-06-17

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Streambert versions prior to 2.5.0
Description A Zip Slip issue exists in the subtitle extraction logic of Streambert, a cross-platform Electron Desktop App. The application fails to sanitize archive entry filenames during the extraction of downloaded ZIP archives. Specifically, the destination file path is created by concatenating the raw archive entry name extracted.name directly to the temporary directory path. This allows a malicious archive containing directory traversal sequences—characters used to navigate the file system hierarchy—to escape the temporary directory and write arbitrary files to the host filesystem based on the application's write permissions.
Recommendations Update to version 2.5.0.

Exploit

Fix

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48055
GHSA-3Q2X-3Q9P-QWFC

Affected Products

Streambert