PostScript Code Injection Vulnerability in SysReptor Professional by Syslifters
CVE-2026-81180

8.8HIGH

Key Information:

Vendor

Syslifters

Status
Vendor
CVE Published:
18 September 2026

What is CVE-2026-81180?

An identified vulnerability in SysReptor Professional allows authenticated users to upload image files that trigger Ghostscript for image processing. This flow can potentially enable an attacker to exploit a race condition involving GnuPG configuration, leading to the execution of attacker-controlled Python code within the application. The executed code runs with the same privileges as the SysReptor application process following a worker restart. This affects all versions prior to 2026.61, with a partial fix available in version 2026.58.

Affected Version(s)

sysreptor < 2026.61

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.