CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-52876

highCVSS 8.8covered by 1 sourcefirst seen 2026-08-18
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the open-path-at-time IPC handler in src/ipc/player.js accepts a renderer-controlled filePath without validating its type or location. If the mpv or VLC launch attempts are skipped or fail, the handler passes filePath to Electron's shell.openPath. A compromised renderer can provide the path of a local executable, script, shortcut, or other file with an executing default handler, causing the operating system to launch it with the privileges of the StreamBERT process and enabling escape from the renderer sandbox. This issue is fixed in version 2.6.0.

⚡ Watch CVE-2026-52876

Get an email if CVE-2026-52876 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-52876

CVE.org record

Embed the live status

CVE-2026-52876 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-52876 status](https://www.csirts.com/badge/CVE-2026-52876)](https://www.csirts.com/cve/CVE-2026-52876)