PT-2026-107229 · Unknown · Ghostscript
CVE-2026-101258
·
Published
2026-10-06
·
Updated
2026-10-07
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ghostscript versions 10.00.0 through 10.07.1
Description
A flaw exists when rendering crafted PostScript or EPS documents, allowing a bypass of the
-dSAFER sandbox. This is achieved by chaining memory corruption during document parsing with the disabling of internal path access controls at runtime. An attacker can deliver a malicious document directly or through formats that delegate rendering to Ghostscript, such as EPS import or print conversion workflows. Successful exploitation allows the execution of arbitrary shell commands in the context of the Ghostscript process, compromising the confidentiality, integrity, and availability of data accessible to that process.Recommendations
Update Ghostscript to version 10.09.0.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript