Remote Code Execution Vulnerability in Streambert App from TrueLockMC
CVE-2026-48046
9.3CRITICAL
What is CVE-2026-48046?
Streambert, a cross-platform Electron Desktop App for streaming and downloading video content, is susceptible to a vulnerability in its auto-updater mechanism. Specifically, versions prior to 2.5.0 contain an unvalidated URL which can be exploited by a compromised renderer process to initiate the main process to download and execute arbitrary binaries. This flaw poses significant security risks as it allows malicious actors to execute unauthorized code on a user's machine. Users are advised to update to version 2.5.0 or later to mitigate this risk. For additional details, refer to the official advisory and release notes.
Affected Version(s)
streambert < 2.5.0
