Junglewise Threat Intelligence

CVE-2026-90491: sanjevirau gsubs code injection via filename argument

CVE-2026-90491 · Severity: medium · CVSS 6.3 · Published 2026-09-13

Executive brief

gsubs is a Node.js/Electron-based subtitle management application. A code injection vulnerability in the filename handling of the renderer process allows an attacker to execute arbitrary code by manipulating the filename parameter, potentially compromising the user's system and data.

Technical details

A code injection vulnerability exists in the showQuerySuccessPage function within renderer/index.js of gsubs up to version 1.0.3. The vulnerability stems from insufficient validation of the filename argument passed to the function, allowing an attacker to inject arbitrary code that executes within the Electron renderer process. The attack vector is remote and requires no authentication; an attacker can craft a malicious filename to trigger code execution. This vulnerability can be exploited to execute arbitrary JavaScript code with the privileges of the Electron renderer process, potentially leading to full system compromise. Public exploits are available, indicating active interest from malicious actors.

Affected products

  • sanjevirau gsubs up to 1.0.3

Timeline

  • 2026-09-13: disclosed
  • exploited: public exploit available

References