Zip Slip Vulnerability in Streambert Desktop App
CVE-2026-48055

10CRITICAL

Key Information:

Vendor

Truelockmc

Vendor
CVE Published:
16 June 2026

What is CVE-2026-48055?

A vulnerability has been detected in the Streambert application, a cross-platform Electron Desktop App designed for streaming and downloading video media. In versions prior to 2.5.0, when the subtitle extraction logic processes ZIP archives, it fails to sanitize filenames during extraction properly. As a result, a specially crafted ZIP file could exploit this flaw, enabling path traversal and allowing unauthorized file writes to any location on the host filesystem where the application has write permissions. This poses significant security concerns, as attackers could leverage this exploit to overwrite or create files outside the intended directory. The issue has been resolved in version 2.5.0.

Affected Version(s)

streambert < 2.5.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.