PT-2026-78239 · Unknown · Streambert

CVE-2026-52877

·

Published

2026-08-18

·

Updated

2026-08-19

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Streambert versions prior to 2.6.0
Description Streambert is a cross-platform Electron Desktop App used for streaming and downloading video content. The open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal() function without validating the protocol. A compromised renderer can submit file: URIs or operating-system-specific custom schemes, allowing the host to open local files, access remote resources through registered handlers, or launch scripts and applications supported by those handlers.
Recommendations Update to version 2.6.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52877
GHSA-J2VW-GG3G-WWQR

Affected Products

Streambert