{"apiVersion":"1.0","identifier":"CVE-2026-52873","description":"Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that removes the Content-Security-Policy header from every response in that session. The redeem window also lacks a setWindowOpenHandler restriction, so script injection in sub.wyzie.io, a loaded third-party resource, or a site reached through navigation executes without CSP constraints and can affect additional windows and persistent session storage. A user must open the Wyzie API key redemption window, and exploitation requires attacker-controlled script content in a loaded page. The resulting renderer script can invoke renderer-exposed application functionality and can be chained with other vulnerabilities to access internal services or sensitive data. This issue is fixed in version 2.6.0.","publishedAt":"2026-08-18T22:16:53","lastModifiedAt":"2026-08-21T20:16:36","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-52873","cvssScore":6.9,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:L/A:N","epssProbability":0.00278,"riskScore":0.71,"affectedProduct":"Streambert","affectedVersions":">=2.5.0,<2.6.0","vulnerabilityType":"Other","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-52873","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-52873","en":"https://www.redsauce.net/en/cves/CVE-2026-52873","fr":"https://www.redsauce.net/fr/cves/CVE-2026-52873","pt":"https://www.redsauce.net/pt/cves/CVE-2026-52873","de":"https://www.redsauce.net/de/cves/CVE-2026-52873","sk":"https://www.redsauce.net/sk/cves/CVE-2026-52873","el":"https://www.redsauce.net/el/cves/CVE-2026-52873"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-52873"}}