true_lock Streambert是德国true_lock个人开发者的一款跨平台的 Electron 桌面应用。 true_lock Streambert 2.6.0之前版本存在安全漏洞,该漏洞源于open-external IPC处理程序未验证协议,将渲染器提供的URL直接传递给Electron的shell.openExternal,可能导致主机打开本地文件、访问远程资源或启动脚本和应用程序。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| truelockmc | streambert | < 2.6.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| truelockmc | streambert | < 2.6.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-52876 | 8.8 HIGH | Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback |
| CVE-2026-52872 | 8.8 HIGH | Streambert: Local File Exfiltration and Overwrite via Subtitle file: Protocol |
| CVE-2026-52875 | 8.4 HIGH | Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler |
| CVE-2026-52873 | 6.9 MEDIUM | Streambert: Global CSP Removal in Wyzie Redeem Window Enables Unconstrained XSS in Electro |
No comments yet