CVE-2026-48046: Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Streambertto a version that resolves this vulnerability.Fixed in 2.5.0 - Compensating control
If possible, prevent/limit the auto-updater IPC handler from allowing a renderer process to trigger downloads/execution using unvalidated updater URLs until Streambert is upgraded to 2.5.0.