PT-2026-95580 · Gnupg+2 · Gnupg+2

CVE-2026-81180

·

Published

2026-09-18

·

Updated

2026-09-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SysReptor Professional versions prior to 2026.61
Description Authenticated users can upload image files that trigger Ghostscript during processing, allowing embedded PostScript to operate within the shared temporary directory. By combining this with a race condition involving GnuPG configuration files in temporary subdirectories, an attacker can force GnuPG to copy malicious Python code into the application code directory. This injected code then executes with the privileges of the SysReptor application process following a worker restart.
Recommendations Update to version 2026.61.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-81180
GHSA-WMF3-GV8J-7QP7

Affected Products

Ghostscript
Gnupg
Sysreptor