Description
SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to cause GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor application process after a worker restart. The Community edition is not affected. Version 2026.58 contains a partial mitigation, and this issue is fully fixed in version 2026.61.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

SysReptor is a pentest reporting platform in which, before the release of version 2026.61, authenticated users of the Professional edition could upload image files that trigger Ghostscript processing involving embedded PostScript code. The PostScript causes Ghostscript to run with access to a shared temporary directory, allowing an attacker to use a race condition with GnuPG configuration files to copy attacker‑controlled Python code into the application code directory. When the worker process restarts, the injected code is executed with the full privileges of the SysReptor service, resulting in remote code execution for the attacker.

Affected Systems

The vulnerability affects Syslifters’ SysReptor Professional edition for all releases preceding 2026.61. The Community edition is not affected. A partial mitigation was introduced in version 2026.58, and the issue is fully resolved in release 2026.61.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity. EPSS information is not available, yet the lack of a KEV listing does not diminish the risk, as the vulnerability requires an authenticated user with upload privileges and leverages a race condition that can be orchestrated through crafted image files. Successful exploitation would grant the attacker code‑execution rights with the same privileges as the SysReptor application process, posing a serious threat to system integrity and confidentiality.

Generated by OpenCVE AI on September 19, 2026 at 11:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade SysReptor to version 2026.61 or later to fully remediate the vulnerability.
  • If upgrade to 2026.61 is not immediately possible, upgrade to 2026.58 to apply the partial mitigation and lower exploitation risk.
  • Restrict uploaded image types to strictly allowed formats and perform thorough input validation before any image processing can be initiated to avoid accidental invocation of Ghostscript.

Generated by OpenCVE AI on September 19, 2026 at 11:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to cause GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor application process after a worker restart. The Community edition is not affected. Version 2026.58 contains a partial mitigation, and this issue is fully fixed in version 2026.61.
Title SysReptor: Authenticated RCE by insecure image processing
Weaknesses CWE-20
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T17:47:02.134Z

Reserved: 2026-08-26T16:26:08.967Z

Link: CVE-2026-81180

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-18T18:17:15.777

Modified: 2026-09-18T18:17:15.930

Link: CVE-2026-81180

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T11:45:08Z

Weaknesses
  • CWE-20

    Improper Input Validation