SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-52875

HIGH · CVSS 8.4 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The vulnerability in Streambert allows an attacker to manipulate the perform-scheduled-backup IPC handler to write and delete files in unauthorized directories, potentially leading to data exposure or loss. This issue arises from improper validation of user-supplied paths, enabling a compromised renderer to exploit the application's file system operations. Organizations using versions prior to 2.6.0 should prioritize updating to the latest version to mitigate this high-severity risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52875
Severity
HIGH
CVSS
8.4
EPSS
0.21%

Original NVD Description

Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and fs.unlinkSync operations without checking that it is inside an authorized backup location. A compromised renderer can choose an absolute path or a relative traversal path to create directories and write a streambert-backup-[timestamp].json file containing renderer-controlled data. The pruning loop can also delete files in that directory whose names begin with streambert-backup- and end with .json. This vulnerability is fixed in 2.6.0.