Arbitrary Command Execution Vulnerability in Ghostscript Software
CVE-2026-101258

7.8HIGH

What is CVE-2026-101258?

A vulnerability exists in Ghostscript that allows an attacker to bypass the -dSAFER sandbox when rendering crafted PostScript or EPS documents. This can lead to executing arbitrary shell commands within the Ghostscript process. The problem stems from a combination of memory corruption during document parsing and the disabling of internal path access controls at execution time. Attackers can exploit this vulnerability by delivering malicious documents, either directly or through other formats that rely on Ghostscript for rendering. If successfully exploited, the attacker could compromise the confidentiality, integrity, and availability of data accessible to the Ghostscript process.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank Akiyoshi Kurita and V12 Security (V12 Security) for reporting this issue.
.