CVE-2026-48056: Truelockmc Streambert

Critical severity, CVSS 10.0. EPSS: 0.6% chance of exploitation in the next 30 days.

Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the  run-download  IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.

Affected products

  • Truelockmc Streambert: before 2.5.0 (fixed in 2.5.0)

Published 2026-08-11. Last modified 2026-09-09.