These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-52876 is a high-severity vulnerability in Streambert, a cross-platform Electron desktop app. The vulnerability allows a compromised renderer to launch local executables or scripts with the privileges of the StreamBERT process, enabling escape from the renderer sandbox. This issue was fixed in version 2.6.0. Defenders managing Electron applications or systems with Streambert installed should asses [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-18T22:16:53.830Z and has not been modified since then. Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index.js creates the partition:wyzie-redeem Electron session and registers an [truncated]
CVE-2026-52872 is a high-severity vulnerability in Streambert, a cross-platform Electron Desktop App. The vulnerability allows a compromised renderer to copy arbitrary files readable by the StreamBERT process into an attacker-controlled writable location, potentially exposing sensitive local data and overwriting existing files. This issue was fixed in version 2.5.0.
A critical vulnerability in Streambert, a cross-platform Electron Desktop App, allows a compromised renderer process to execute arbitrary local binaries with the application's privileges due to improper validation of executable paths supplied to the run-download IPC handler. This issue was addressed in version 2.5.0. The vulnerability has a CVSS score of 10 and a severity of CRITICAL. Streambert versions [truncated]
CVE-2026-48046 is a critical vulnerability in Streambert, a cross-platform Electron Desktop App, where versions prior to 2.5.0 contain an unvalidated auto-updater URL vulnerability. This allows a compromised renderer process to make the main process download and execute an arbitrary binary, resulting in remote code execution. The vulnerability was patched in version 2.5.0.
Streambert 2.4.0 and prior versions contain a high-severity Zip Slip vulnerability in subtitle extraction logic, allowing path traversal and arbitrary file writes. The application fails to sanitize archive entry filenames during extraction, enabling a malicious archive to escape temporary directory boundaries and write payloads anywhere on the host filesystem with current write permissions. This issue is [truncated]