PT-2026-78238 · Unknown · Streambert
CVE-2026-52876
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
8.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Streambert versions prior to 2.6.0
Description
Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The
open-path-at-time IPC handler in src/ipc/player.js accepts a filePath controlled by the renderer without validating its type or location. If attempts to launch via mpv or VLC are skipped or fail, the handler passes the filePath to Electron's shell.openPath. A compromised renderer can provide the path to a local executable, script, shortcut, or any file with an executing default handler, allowing the operating system to launch it with the privileges of the StreamBERT process and enabling a sandbox escape.Recommendations
Update to version 2.6.0.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Streambert