Streambert fixed a critical arbitrary file write flaw in version 2.5.0 after maintainers disclosed multiple security issues, including GHSA-3q2x-3q9p-qwfc. The vulnerability affects Streambert 2.4.0 and earlier, where subtitle extraction in src/ipc/subtitles.js concatenates ZIP entry names into a temporary path without sanitization, allowing path traversal during archive extraction. The issue was reported by jeremyHOT and fixed with the 2.5.0 release.
The flaw, tracked as CVE-2026-48055, allows a malicious subtitle ZIP archive delivered through Streambert’s subtitle download workflow to escape the intended temporary directory and write files anywhere permitted by the application’s privileges. The advisory links exploitation to the get-subtitle-url IPC channel and recommends sanitizing extracted filenames, while public vulnerability records rate the bug CVSS 10.0 and describe it as remotely exploitable. Users are advised to upgrade to Streambert 2.5.0 immediately.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-16, CVE-2026-48055 was published for the Streambert arbitrary file write vulnerability in subtitle extraction. The entry rates the issue critical with a CVSS 3.1 score of 10.0 and identifies Streambert 2.5.0 as the fixed version.
On 2026-05-22, a GitHub security advisory disclosed a high-severity arbitrary file write (Zip Slip) vulnerability in Streambert affecting versions up to 2.4.0. The advisory says the issue was patched in version 2.5.0 and includes technical details and a proof of concept involving malicious subtitle ZIP archives.
On 2026-05-22, truelockmc released Streambert version 2.5.0. The release notes state that it fixes three critical vulnerabilities, including GHSA-3q2x-3q9p-qwfc, with fixes credited to jeremyHOT and truelockmc.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.