Back

HIGH

Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback

Published Aug 18, 2026

Description

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the path of a local executable, script, shortcut, or other file with an executing default handler, causing the operating system to launch it with the privileges of the StreamBERT process and enabling escape from the renderer sandbox. This issue is fixed in version 2.6.0.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 19, 2026
Reserved Jun 8, 2026

CISA Vulnrichment

Updated Aug 19, 2026

NVD

Status Deferred
Modified Sep 9, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Aug 18, 2026
Updated Aug 19, 2026

GitHub

No data