CVE-2026-90491: sanjevirau gsubs Electron index.js showQuerySuccessPage code injection
A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
Which releases are known to be affected?
sanjevirau gsubs versions up to and including 1.0.3 are identified as affected. The issue is in the Electron component's renderer/index.js file, specifically the showQuerySuccessPage function.
What does an attacker need to exploit this issue?
An attacker needs to manipulate the filename argument passed to showQuerySuccessPage. The attack can be performed remotely and requires user interaction, but no attacker privileges are required.
Is exploit code available?
Yes. A public exploit is available and could be used in attacks.
Is a vendor fix available?
The provided information does not identify a fix. It states that the vendor was contacted early about the disclosure but did not respond.