true_lock Streambert是德国true_lock个人开发者的一款跨平台的 Electron 桌面应用。 true_lock Streambert 2.5.0版本至2.6.0之前版本存在安全漏洞,该漏洞源于wyzie-open-redeem IPC处理程序移除Content-Security-Policy标头且缺少setWindowOpenHandler限制,可能导致脚本注入,从而影响其他窗口和持久会话存储,并可能访问内部服务或敏感数据。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| truelockmc | streambert | < 2.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| truelockmc | streambert | < 2.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52876 | 8.8 HIGH | Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback |
| CVE-2026-52872 | 8.8 HIGH | Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol |
| CVE-2026-52875 | 8.4 HIGH | Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler |
| CVE-2026-52877 | 8.3 HIGH | Streambert : Insecure Protocol Execution in open-external IPC Handler |
No comments yet