PT-2026-78235 · Unknown · Streambert

CVE-2026-52872

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Streambert versions prior to 2.5.0
Description Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The downloadSubtitleFile function in src/ipc/downloads.js, accessed via the run-download IPC channel, improperly handles subtitle URLs using the file: URI scheme. By controlling the downloadPath variable and providing a malicious URI, a compromised renderer can use fs.copyFileSync to copy any file readable by the process to an arbitrary writable location. This allows for the exfiltration of sensitive local data or the overwriting of existing writable files.
Recommendations Update to version 2.5.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52872
GHSA-V74H-2468-RXHH

Affected Products

Streambert