CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52875

unknowncovered by 1 sourcefirst seen 2026-08-18
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes settings.path from a renderer-supplied object and uses the resulting directory for fs.mkdirSync, fs.writeFileSync, fs.readdirSync, and fs.unlinkSync operations without checking that it is inside an authorized backup location. A compromised renderer can choose an absolute path or a relative traversal path to create directories and write a streambert-backup-[timestamp].json file containing renderer-controlled data. The pruning loop can also delete files in that directory whose names begin with streambert-backup- and end with .json. This vulnerability is fixed in 2.6.0.

⚡ Watch CVE-2026-52875

Get an email if CVE-2026-52875 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-52875

CVE.org record

Embed the live status

CVE-2026-52875 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52875 status](https://www.csirts.com/badge/CVE-2026-52875)](https://www.csirts.com/cve/CVE-2026-52875)