CVE-2026-52875
Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and fs.unlinkSync operations without checking that it is inside an authorized backup location. A compromised renderer can choose an absolute path or a relative traversal path to create directories and write a streambert-backup-[timestamp].json file containing renderer-controlled data. The pruning loop can also delete files in that directory whose names begin with streambert-backup- and end with .json. This vulnerability is fixed in 2.6.0.
| CWE | CWE-22 CWE-73 |
| Vendor | truelockmc |
| Product | streambert |
| Published | Aug 18, 2026 |
Get instant alerts for truelockmc streambert
Be the first to know when new unknown vulnerabilities affecting truelockmc streambert are published โ delivered to Slack, Telegram or Discord.