PostScript Code Injection Vulnerability in SysReptor Professional by Syslifters
CVE-2026-81180
8.8HIGH
What is CVE-2026-81180?
An identified vulnerability in SysReptor Professional allows authenticated users to upload image files that trigger Ghostscript for image processing. This flow can potentially enable an attacker to exploit a race condition involving GnuPG configuration, leading to the execution of attacker-controlled Python code within the application. The executed code runs with the same privileges as the SysReptor application process following a worker restart. This affects all versions prior to 2026.61, with a partial fix available in version 2026.58.
Affected Version(s)
sysreptor < 2026.61
