CVE-2026-52872 | truelockmc Streambert up to 2.4.x Subtitle Download src/ipc/downloads.js downloadSubtitleFile downloadPath path traversal

SecurityVulns

A vulnerability was found in truelockmc Streambert up to 2.4.x and classified as problematic. Affected by this issue is the function downloadSubtitleFile of the file src/ipc/downloads.js of the component Subtitle Download. Executing a manipulation of the argument downloadPath can lead to path traversal.

The identification of this vulnerability is CVE-2026-52872. The attack can only be executed locally. There is no exploit available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More