File Overwrite Vulnerability in StreamBERT by TrueLockMC
CVE-2026-52872

8.8HIGH

Key Information:

Vendor

Truelockmc

Vendor
CVE Published:
18 August 2026

What is CVE-2026-52872?

StreamBERT, a cross-platform Electron desktop application for streaming and downloading video content, has a security issue that affects versions prior to 2.5.0. The vulnerability stems from the downloadSubtitleFile utility, which accepts a user-supplied subtitle URL via the file: URI scheme. This mechanism allows an attacker to exploit the application's ability to define download paths, leading to the potential for any file readable by the StreamBERT process to be copied into any writable location determined by the attacker. This could expose sensitive local data and overwrite existing files, severely compromising user security.

Affected Version(s)

streambert < 2.5.0

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.