CVE-2026-52872 | truelockmc Streambert up to 2.4.x Subtitle Download src/ipc/downloads.js downloadSubtitleFile downloadPath path traversal
A vulnerability was found in truelockmc Streambert up to 2.4.x and classified as problematic. Affected by this issue is the function downloadSubtitleFile of the file src/ipc/downloads.js of the component Subtitle Download. Executing a manipulation of the argument downloadPath can lead to path traversal.
The identification of this vulnerability is CVE-2026-52872. The attack can only be executed locally. There is no exploit available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More