VYPR

Streambert

by Truelockmc

Source repositories

CVEs (5)

  • CVE-2026-48056CriAug 11, 2026
    risk 0.65cvss 10.0epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with…

  • CVE-2026-48055CriJun 17, 2026
    risk 0.65cvss 10.0epss 0.01

    Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vulnerability was identified in Streambert's subtitle extraction logic. The application does not sanitize archive entry filenames…

  • CVE-2026-52875HigAug 18, 2026
    risk 0.48cvss —epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync,…

  • CVE-2026-52877HigAug 18, 2026
    risk 0.47cvss 8.3epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-external IPC handler in src/ipc/downloads.js passes a renderer-supplied url directly to Electron's shell.openExternal without validating its protocol. A…

  • CVE-2026-52873MedAug 18, 2026
    risk 0.38cvss 6.9epss 0.00

    Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that…