PT-2026-78238 · Unknown · Streambert

CVE-2026-52876

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Streambert versions prior to 2.6.0
Description Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The open-path-at-time IPC handler in src/ipc/player.js accepts a filePath controlled by the renderer without validating its type or location. If attempts to launch via mpv or VLC are skipped or fail, the handler passes the filePath to Electron's shell.openPath. A compromised renderer can provide the path to a local executable, script, shortcut, or any file with an executing default handler, allowing the operating system to launch it with the privileges of the StreamBERT process and enabling a sandbox escape.
Recommendations Update to version 2.6.0.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52876
GHSA-85VF-2QWC-QPM4

Affected Products

Streambert