{"id":"CVE-2026-48056","title":"Streambert is a cross-platform Electron Desktop App to stream and download video content","summary":"Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0  improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process t…","severity":"critical","cvss":10,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-20","CWE-749"],"published":"2026-08-11","updated":"2026-09-09","sourceUpdated":"2026-09-09T21:02:22.660","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-48056","references":[{"url":"https://github.com/truelockmc/streambert/releases/tag/2.5.0","label":"security-advisories@github.com"},{"url":"https://github.com/truelockmc/streambert/security/advisories/GHSA-x267-77m6-qjc9","label":"security-advisories@github.com"},{"url":"https://github.com/truelockmc/streambert/security/advisories/GHSA-x267-77m6-qjc9","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00479,"epssPercentile":0.40396,"ingestedAt":"2026-09-09T21:22:45.527Z","slug":"CVE-2026-48056","body":"## Overview\n\nStreambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0  improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":55,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}