VYPR

streambert

by Streambert

CVEs (3)

  • CVE-2026-52876HigAug 18, 2026
    risk 0.50cvss 8.8epss

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch…

  • CVE-2026-52875HigAug 18, 2026
    risk 0.48cvss epss

    Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync,…

  • CVE-2026-52873MedAug 18, 2026
    risk 0.38cvss 6.9epss

    Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an onHeadersReceived hook that…