File Overwrite Vulnerability in StreamBERT by TrueLockMC
CVE-2026-52872
8.8HIGH
What is CVE-2026-52872?
StreamBERT, a cross-platform Electron desktop application for streaming and downloading video content, has a security issue that affects versions prior to 2.5.0. The vulnerability stems from the downloadSubtitleFile utility, which accepts a user-supplied subtitle URL via the file: URI scheme. This mechanism allows an attacker to exploit the application's ability to define download paths, leading to the potential for any file readable by the StreamBERT process to be copied into any writable location determined by the attacker. This could expose sensitive local data and overwrite existing files, severely compromising user security.
Affected Version(s)
streambert < 2.5.0
