CVE-2026-48056: Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Streambertto a version that resolves this vulnerability.Fixed in 2.5.0