PT-2026-95580 · Gnupg+2 · Gnupg+2
CVE-2026-81180
·
Published
2026-09-18
·
Updated
2026-09-23
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SysReptor Professional versions prior to 2026.61
Description
Authenticated users can upload image files that trigger Ghostscript during processing, allowing embedded PostScript to operate within the shared temporary directory. By combining this with a race condition involving GnuPG configuration files in temporary subdirectories, an attacker can force GnuPG to copy malicious Python code into the application code directory. This injected code then executes with the privileges of the SysReptor application process following a worker restart.
Recommendations
Update to version 2026.61.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ghostscript
Gnupg
Sysreptor