PT-2026-78239 · Unknown · Streambert
CVE-2026-52877
·
Published
2026-08-18
·
Updated
2026-08-19
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Streambert versions prior to 2.6.0
Description
Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The
open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal() function without validating the protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, allowing the host to open local files, access remote resources through registered handlers, or launch scripts and applications supported by those handlers.Recommendations
Update to version 2.6.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Streambert