Zip Slip Vulnerability in Streambert Desktop App
CVE-2026-48055
10CRITICAL
What is CVE-2026-48055?
A vulnerability has been detected in the Streambert application, a cross-platform Electron Desktop App designed for streaming and downloading video media. In versions prior to 2.5.0, when the subtitle extraction logic processes ZIP archives, it fails to sanitize filenames during extraction properly. As a result, a specially crafted ZIP file could exploit this flaw, enabling path traversal and allowing unauthorized file writes to any location on the host filesystem where the application has write permissions. This poses significant security concerns, as attackers could leverage this exploit to overwrite or create files outside the intended directory. The issue has been resolved in version 2.5.0.
Affected Version(s)
streambert < 2.5.0
