๐Ÿ” CVE Alert

CVE-2026-52875

UNKNOWN 0.0

Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and fs.unlinkSync operations without checking that it is inside an authorized backup location. A compromised renderer can choose an absolute path or a relative traversal path to create directories and write a streambert-backup-[timestamp].json file containing renderer-controlled data. The pruning loop can also delete files in that directory whose names begin with streambert-backup- and end with .json. This vulnerability is fixed in 2.6.0.

CWE CWE-22 CWE-73
Vendor truelockmc
Product streambert
Published Aug 18, 2026
Stay Ahead of the Next One

Get instant alerts for truelockmc streambert

Be the first to know when new unknown vulnerabilities affecting truelockmc streambert are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

truelockmc / streambert
< 2.6.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/truelockmc/streambert/security/advisories/GHSA-c64m-cx97-6rc9 github.com: https://github.com/truelockmc/streambert/pull/149 github.com: http://github.com/truelockmc/streambert/commit/43566ed031183b046675761c9813c5379b619269