CVE-2026-48046: Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Streambertto a version that resolves this vulnerability.Fixed in 2.5.0 - Compensating control
If possible, prevent/limit the auto-updater IPC handler from allowing a renderer process to trigger downloads/execution using unvalidated updater URLs until Streambert is upgraded to 2.5.0.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48046?
CVE-2026-48046 has a risk rating of 77, indicating a high severity level.
How do I fix CVE-2026-48046?
To fix CVE-2026-48046, upgrade Streambert to version 2.5.0 or later.
What does CVE-2026-48046 affect?
CVE-2026-48046 affects the Streambert application, specifically versions prior to 2.5.0.
What type of vulnerability is reported in CVE-2026-48046?
CVE-2026-48046 is a remote code execution (RCE) vulnerability via an unvalidated auto-updater IPC handler.
How can attackers exploit CVE-2026-48046?
Attackers can exploit CVE-2026-48046 by using a compromised renderer process to make the main process download and execute arbitrary binaries.