Arbitrary Code Execution Risk in Streambert by TrueLock
CVE-2026-48056
10CRITICAL
What is CVE-2026-48056?
The Streambert application, developed by TrueLock, is a cross-platform Electron Desktop App designed for streaming and downloading video content. Versions prior to 2.5.0 are vulnerable due to improper validation of executable paths supplied to the run-download IPC handler. This flaw allows an attacker to exploit a compromised renderer process to execute arbitrary local binaries with the application's privileges, potentially leading to unauthorized actions on the host system. Users are urged to upgrade to version 2.5.0 or later, which includes a patch addressing this critical security issue.
Affected Version(s)
streambert < 2.5.0
