File System Manipulation Vulnerability in Streambert by TrueLockMC
CVE-2026-52875
8.4HIGH
What is CVE-2026-52875?
The vulnerability in Streambert prior to version 2.6.0 allows a compromised renderer to manipulate file system operations through the perform-scheduled-backup IPC handler. It utilizes the settings.path from the renderer-supplied object without verifying if the provided path is within an authorized backup directory. This flaw could lead to arbitrary file creation or deletion, enabling attackers to write files containing malicious data or remove critical backups. Users are advised to upgrade to version 2.6.0 to mitigate this risk.
Affected Version(s)
streambert < 2.6.0
