CRITICAL 9.3 NVD
CVE-2026-48046
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulner
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability that allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. Version 2.5.0 contains a patch.
References
- https://github.com/truelockmc/streambert/releases/tag/2.5.0
- https://github.com/truelockmc/streambert/security/advisories/GHSA-vj74-r9xm-37mj
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-11 via NVD.
Risk Timeline
CVE Disclosed2026-08-11 · -1 days ago
Remediation Resources
vulnfeed aggregates 9844 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.