DescriptionStreambert through 2.5.0 contains a server-side request forgery vulnerability that allows unauthenticated attackers to issue arbitrary outbound HTTP requests by exploiting an unprotected local Node.js proxy endpoint accepting fully attacker-controlled URLs with no host or IP allowlist. Attackers can inject malicious URLs through the /proxy?url= parameter, leveraging same-origin JavaScript execution in the player page to relay requests through the Node.js main process and exfiltrate sensitive data such as cloud instance metadata credentials or access locally running services.