Impact
The vulnerability lies in the run-download IPC handler of Streambert, which fails to validate the executable paths supplied. A compromised renderer process can instruct the handler to launch any local binary under the application’s privileges, enabling arbitrary code execution on the host. This flaw corresponds to CWE-20 and CWE-749 and can allow a malicious actor to run arbitrary programs, potentially escalating privileges or installing malware.
Affected Systems
The flaw affects the Streambert desktop application distributed by truelockmc. All releases prior to 2.5.0 contain the vulnerability. The 2.5.0 release includes the necessary patch.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. Because the flaw requires a compromised renderer process, the attack vector is local but could be executed by an attacker who can deliver malicious content to the renderer or compromise the application itself. No exploitation probability data is available, and the vulnerability is not yet listed in the CISA KEV catalog, but the lack of a fix in older versions still poses a high risk for exposed systems.
OpenCVE Enrichment