CVE-2026-48056: Streambert Vulnerable to Arbitrary Binary Execution via Downloader IPC Handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Streambertto a version that resolves this vulnerability.Fixed in 2.5.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48056?
The severity of CVE-2026-48056 is critical with a score of 10.
How do I fix CVE-2026-48056?
To fix CVE-2026-48056, update to Streambert version 2.5.0 or later.
What type of vulnerability is CVE-2026-48056?
CVE-2026-48056 is an input validation vulnerability that allows arbitrary binary execution.
What impact does CVE-2026-48056 have on user systems?
CVE-2026-48056 allows a compromised renderer process to execute arbitrary local binaries with the application's privileges.
Which versions of Streambert are affected by CVE-2026-48056?
Versions of Streambert prior to 2.5.0 are affected by CVE-2026-48056.