PT-2026-78236 · Unknown · Streambert
CVE-2026-52873
·
Published
2026-08-18
·
Updated
2026-08-21
CVSS v3.1
6.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Streambert versions 2.5.0 through 2.5.9
Description
Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The
wyzie-open-redeem IPC handler in index.js creates a partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Security-Policy (CSP) header from every response in that session. CSP is a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting (XSS). Additionally, the redeem window lacks a setWindowOpenHandler restriction. This allows script injection in sub.wyzie.io, a loaded third-party resource, or a site reached through navigation to execute without CSP constraints, potentially affecting other windows and persistent session storage. Exploitation occurs when a user opens the Wyzie API key redemption window and the loaded page contains attacker-controlled script content. The resulting renderer script can invoke application functionality exposed to the renderer and may be chained with other issues to access sensitive data or internal services.Recommendations
Update to version 2.6.0.
Exploit
Fix
XSS
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Streambert