Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback
Published Aug 18, 2026
8.8
HIGHCVSS 3.1
EPSS 0.20%
Description
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the path of a local executable, script, shortcut, or other file with an executing default handler, causing the operating system to launch it with the privileges of the StreamBERT process and enabling escape from the renderer sandbox. This issue is fixed in version 2.6.0.
Affected products
-
Affected
- < 2.6.0
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Truelockmc | Streambert | unknown | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (5)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62198 Advisory
- https://github.com/truelockmc/streambert/commit/43566ed031183b046675761c9813c5379b619269 x_refsource_MISC
- https://github.com/truelockmc/streambert/pull/149 x_refsource_MISC
- https://github.com/truelockmc/streambert/releases/tag/2.6.0 x_refsource_MISC
- https://github.com/truelockmc/streambert/security/advisories/GHSA-85vf-2qwc-qpm4 x_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-62198 | Advisory | |
| https://github.com/truelockmc/streambert/commit/43566ed031183b046675761c9813c5379b619269 | x_refsource_MISC | |
| https://github.com/truelockmc/streambert/pull/149 | x_refsource_MISC | |
| https://github.com/truelockmc/streambert/releases/tag/2.6.0 | x_refsource_MISC | |
| https://github.com/truelockmc/streambert/security/advisories/GHSA-85vf-2qwc-qpm4 | x_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
Red Hat
No data
GitHub
No data