PT-2026-107229 · Unknown · Ghostscript

CVE-2026-101258

·

Published

2026-10-06

·

Updated

2026-10-07

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ghostscript versions 10.00.0 through 10.07.1
Description A flaw exists when rendering crafted PostScript or EPS documents, allowing a bypass of the -dSAFER sandbox. This is achieved by chaining memory corruption during document parsing with the disabling of internal path access controls at runtime. An attacker can deliver a malicious document directly or through formats that delegate rendering to Ghostscript, such as EPS import or print conversion workflows. Successful exploitation allows the execution of arbitrary shell commands in the context of the Ghostscript process, compromising the confidentiality, integrity, and availability of data accessible to that process.
Recommendations Update Ghostscript to version 10.09.0.

Exploit

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101258

Affected Products

Ghostscript