Impact
A weakness exists in sanjevirau gsubs up to version 1.0.3 that allows manipulation of the `filename` argument passed to the `showQuerySuccessPage` function in `renderer/index.js`. This manipulation can lead to code injection, giving an attacker the ability to execute arbitrary code in the context of the Electron application. The description confirms that the attack can be performed remotely and that proof‑of‑concept exploits have already been made publicly available.
Affected Systems
The affected product is sanjevirau gsubs, specifically version 1.0.3 or older. The vulnerability resides in the Electron component of the application, so any deployment that includes this module is potentially exposed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The vulnerability is not listed in ability to inject code remotely is inherently risky. An attacker could compromise the application, elevate privileges, or exfiltrate data by exploiting this flaw, especially if no other safeguards are in place.
OpenCVE Enrichment