Code Injection Vulnerability in sanjevirau gsubs by Electron
CVE-2026-90491
Key Information:
- Vendor
Sanjevirau
- Status
- Vendor
- CVE Published:
- 13 September 2026
Badges
What is CVE-2026-90491?
A code injection vulnerability exists in the sanjevirau gsubs product, specifically in the function showQuerySuccessPage within the renderer/index.js file. By manipulating the argument 'filename', an attacker can execute arbitrary code remotely. The potential exploit has been publicly disclosed, making it essential for users to implement necessary security measures promptly. The vendor has been notified about the issue but has not responded to the inquiry.
Affected Version(s)
gsubs 1.0.0
gsubs 1.0.1
gsubs 1.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
