Impact
SysReptor is a pentest reporting platform in which, before the release of version 2026.61, authenticated users of the Professional edition could upload image files that trigger Ghostscript processing involving embedded PostScript code. The PostScript causes Ghostscript to run with access to a shared temporary directory, allowing an attacker to use a race condition with GnuPG configuration files to copy attacker‑controlled Python code into the application code directory. When the worker process restarts, the injected code is executed with the full privileges of the SysReptor service, resulting in remote code execution for the attacker.
Affected Systems
The vulnerability affects Syslifters’ SysReptor Professional edition for all releases preceding 2026.61. The Community edition is not affected. A partial mitigation was introduced in version 2026.58, and the issue is fully resolved in release 2026.61.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. EPSS information is not available, yet the lack of a KEV listing does not diminish the risk, as the vulnerability requires an authenticated user with upload privileges and leverages a race condition that can be orchestrated through crafted image files. Successful exploitation would grant the attacker code‑execution rights with the same privileges as the SysReptor application process, posing a serious threat to system integrity and confidentiality.
OpenCVE Enrichment