CVE-2026-48046
Streambert Vulnerable to Remote Code Execution (RCE) via Unvalidated Auto-Updater IPC Handler
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
| CWE | CWE-494 |
| Vendor | truelockmc |
| Product | streambert |
| Published | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for truelockmc streambert
Be the first to know when new unknown vulnerabilities affecting truelockmc streambert are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
truelockmc / streambert
< 2.5.0