CVE-2026-48046: Truelockmc Streambert
Critical severity, CVSS 9.3. EPSS: 0.4% chance of exploitation in the next 30 days.
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
Affected products
- Truelockmc Streambert: before 2.5.0 (fixed in 2.5.0)
Published 2026-08-11. Last modified 2026-09-09.