PT-2026-78235 · Unknown · Streambert
CVE-2026-52872
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Streambert versions prior to 2.5.0
Description
Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The
downloadSubtitleFile function in src/ipc/downloads.js, accessed via the run-download IPC channel, improperly handles subtitle URLs using the file: URI scheme. By controlling the downloadPath variable and providing a malicious URI, a compromised renderer can use fs.copyFileSync to copy any file readable by the process to an arbitrary writable location. This allows for the exfiltration of sensitive local data or the overwriting of existing writable files.Recommendations
Update to version 2.5.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Streambert