Arbitrary Code Execution Risk in Streambert by TrueLock
CVE-2026-48056

10CRITICAL

Key Information:

Vendor

Truelockmc

Vendor
CVE Published:
11 August 2026

What is CVE-2026-48056?

The Streambert application, developed by TrueLock, is a cross-platform Electron Desktop App designed for streaming and downloading video content. Versions prior to 2.5.0 are vulnerable due to improper validation of executable paths supplied to the run-download IPC handler. This flaw allows an attacker to exploit a compromised renderer process to execute arbitrary local binaries with the application's privileges, potentially leading to unauthorized actions on the host system. Users are urged to upgrade to version 2.5.0 or later, which includes a patch addressing this critical security issue.

Affected Version(s)

streambert < 2.5.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.