---
id: CVE-2026-90491
title: A weakness has been identified in sanjevirau gsubs up to 1.0.3
summary: >-
  A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is
  the function showQuerySuccessPage of the file renderer/index.js of the
  component Electron. Executing a manipulation of the argument filename can lead
  to code inj…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-94
vendor: sanjevirau
product: gsubs
affected:
  - gsubs 1.0.0
  - gsubs 1.0.1
  - gsubs 1.0.2
  - gsubs 1.0.3
published: '2026-09-13'
updated: '2026-09-15'
sourceUpdated: '2026-09-15T18:19:36.580'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90491'
references:
  - url: 'https://github.com/LeoWSY-hashblue/cve-electron-2/blob/master/gsubs/cve.md'
    label: cna@vuldb.com
  - url: 'https://github.com/LeoWSY-hashblue/cve-electron-2/tree/master/gsubs/poc'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-90491'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/891691'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403079'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/403079/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.00423
epssPercentile: 0.33876
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-15T17:16:14.198271Z'
ingestedAt: '2026-09-14T15:23:07.477Z'
---

## Overview

A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
