Impact
Streambert’s auto‑updater URL handling lacks validation. A renderer process that has already compromised, or can be tricked by a malicious web page, can instruct the main process to download and run an arbitrary binary. The flaw is a CWE‑494 trust boundary violation. The result is remote code execution on the host machine with privileges of the application.
Affected Systems
The affected product is Streambert, a cross‑platform Electron desktop application developed by TrueLockMC. All releases prior to 2.5.0 are vulnerable; version 2.5.0 contains a fix.
Risk and Exploitability
The CVSS score of 9.3 marks this flaw as critical. The EPSS score is unavailable, so the current exploitation probability is uncertain, but the lack of a KEV listing does not diminish the need for immediate action. Exploitation requires a renderer that can send a malicious IPC request, so a local compromise or social engineering that leads a user to run malicious content may be sufficient. Once triggered, the attacker gains full control of the system as the main process runs arbitrary code.
OpenCVE Enrichment