Junglewise Threat Intelligence

CVE-2026-81180: SysReptor Professional arbitrary code execution via image upload

CVE-2026-81180 · Severity: high · CVSS 8.8 · Published 2026-09-18

Vendors: Syslifters.

Executive brief

SysReptor is a pentest reporting platform used to generate and manage security assessment documentation. Prior to version 2026.61, authenticated users of the Professional edition can upload image files that trigger image processing through Ghostscript, combined with a race condition in GnuPG configuration handling, allowing attackers to inject and execute arbitrary Python code with application privileges.

Technical details

The vulnerability involves a chain: malicious image uploads trigger Ghostscript processing with embedded PostScript in a shared temporary directory; a race condition allows the attacker to manipulate GnuPG configuration files in temporary subdirectories, causing GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor worker process after restart. Authentication is required; the Community edition is not affected. Version 2026.61 fully remedies this issue.

Affected products

  • Syslifters SysReptor Professional prior to 2026.61

Timeline

  • 2026-09-18: disclosed

References