← Volver al buscador de CVEs

CVE-2026-52872

Streambert

Descripción

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through the run-download IPC channel, accepts a renderer-supplied subtitle url using the file: URI scheme and passes its decoded pathname to fs.copyFileSync. The renderer also controls downloadPath, which determines the destination path. A compromised renderer can therefore copy any file readable by the StreamBERT process into an attacker-chosen writable location, exposing sensitive local data, and can overwrite existing writable files. This vulnerability is fixed in 2.5.0.

CVSS 8.8EPSS 0.14200000000000002%Riesgo 0.89
Ver fuente
Publicación
2026-08-18 22:16:53
Versiones afectadas
<2.5.0
Tipo
Otro
Última modificación
2026-08-19 17:19:22
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H