Junglewise Threat Intelligence

CVE-2026-48056: Streambert arbitrary binary execution via downloader IPC handler

CVE-2026-48056 · Severity: critical · CVSS 10 · Published 2026-08-11

Technologies: Truelockmc Streambert. Vendors: Truelockmc.

Executive brief

Streambert is a cross-platform desktop application used to stream and download video content. Versions prior to 2.5.0 allow a compromised renderer process to execute arbitrary system binaries with the application's privileges, potentially giving an attacker full control over a user's system. An attacker could exploit this through malicious video feeds or injection attacks to run malware or steal sensitive data.

Technical details

The vulnerability is an improper input validation flaw (CWE-20) in the run-download IPC handler located in src/ipc/downloads.js. The handler accepts a binaryPath argument from the renderer process and executes it via Node.js spawn without validating the file path, enabling a compromised renderer (via XSS or malicious feed injection) to execute arbitrary local binaries such as cmd.exe, powershell.exe, or /bin/sh with the application's privileges. The attack requires the renderer process to be compromised but does not require additional user interaction. Version 2.5.0 patches the vulnerability by validating that the binary path resides in a legitimate downloader directory containing an _internal subdirectory.

Affected products

  • truelockmc Streambert < 2.5.0

Timeline

  • 2026-05-22: disclosed
  • 2026-05-22: patched: Version 2.5.0 released with patch

References

Related threats