Junglewise Threat Intelligence

CVE-2026-48055: truelockmc Streambert Zip Slip in subtitle extraction

CVE-2026-48055 · Severity: critical · CVSS 10 · Published 2026-06-17

Technologies: Truelockmc Streambert. Vendors: Truelockmc.

Executive brief

Streambert is a desktop application used for streaming and downloading video media. A critical security flaw in its subtitle processing allows a malicious actor to write files anywhere on a user's computer. This could be used to plant malicious software or overwrite system files, potentially leading to a full system compromise. Users should update to version 2.5.0 immediately to resolve this issue.

Technical details

A 'Zip Slip' (path traversal) vulnerability exists in Streambert's subtitle extraction logic within `src/ipc/subtitles.js`. The application fails to sanitize archive entry filenames when processing ZIP files downloaded via the `get-subtitle-url` IPC channel. By concatenating raw entry names directly to the temporary directory path, the application allows specially crafted ZIP files containing `../` sequences to escape the intended directory. An attacker can exploit this to write arbitrary files to the host filesystem with the permissions of the application. The vulnerability has been addressed in version 2.5.0 by implementing `path.basename()` sanitization on extracted filenames.

Affected products

  • truelockmc Streambert <= 2.4.0

Timeline

  • 2026-05-22: patched: Version 2.5.0 released
  • 2026-06-17: disclosed: Public advisory and CVE published

References

Related threats