CyberRota Analysis
AI-GeneratedVersions of the Streambert Electron Desktop App prior to 2.5.0 are vulnerable due to improper validation of executable paths in the run-download IPC handler, which allows a compromised renderer process to execute arbitrary local binaries with the application's privileges. This critical vulnerability (CVSS 10.0) poses a significant risk as it can lead to unauthorized code execution on affected systems. Organizations using Streambert should prioritize updating to version 2.5.0 or later to mitigate this severe security risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable paths supplied to the run-download IPC handler, allowing a compromised renderer process to execute arbitrary local binaries with the application’s privileges. Version 2.5.0 contains a patch.