Description
A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Code Injection
Action: Assess Impact
AI Analysis

Impact

A weakness exists in sanjevirau gsubs up to version 1.0.3 that allows manipulation of the `filename` argument passed to the `showQuerySuccessPage` function in `renderer/index.js`. This manipulation can lead to code injection, giving an attacker the ability to execute arbitrary code in the context of the Electron application. The description confirms that the attack can be performed remotely and that proof‑of‑concept exploits have already been made publicly available.

Affected Systems

The affected product is sanjevirau gsubs, specifically version 1.0.3 or older. The vulnerability resides in the Electron component of the application, so any deployment that includes this module is potentially exposed.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in ability to inject code remotely is inherently risky. An attacker could compromise the application, elevate privileges, or exfiltrate data by exploiting this flaw, especially if no other safeguards are in place.

Generated by OpenCVE AI on September 15, 2026 at 17:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Check whether your installation of sanjevirau gsubs is version 1.0.3 or lower and upgrade to a patched release when it becomes available.
  • Add input validation or sanitization for the `filename` argument in `showQuerySuccessPage`, ensuring that only expected characters or paths are accepted to prevent injection.
  • If possible, disable or remove the Electron component that handles `showQuerySuccessPage` from your application to eliminate the attack vector.

Generated by OpenCVE AI on September 15, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the file renderer/index.js of the component Electron. Executing a manipulation of the argument filename can lead to code injection. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title sanjevirau gsubs Electron index.js showQuerySuccessPage code injection
First Time appeared Sanjevirau
Sanjevirau gsubs
Weaknesses CWE-74
CWE-94
CPEs cpe:2.3:a:sanjevirau:gsubs:*:*:*:*:*:*:*:*
Vendors & Products Sanjevirau
Sanjevirau gsubs
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sanjevirau Gsubs
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T17:16:29.457Z

Reserved: 2026-09-12T08:03:44.328Z

Link: CVE-2026-90491

cve-icon Vulnrichment

Updated: 2026-09-15T17:16:19.179Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T02:17:03.097

Modified: 2026-09-15T18:19:36.580

Link: CVE-2026-90491

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')