CVE-2026-81180
8.8Syslifters · sysreptor
Authenticated users of SysReptor Professional can achieve remote code execution by uploading malicious image files that exploit Ghostscript and a race condition to inject Python code.
Executive summary
A critical vulnerability in SysReptor Professional allows authenticated attackers to achieve remote code execution, posing a severe risk of full system compromise.
Vulnerability
The application fails to properly validate image uploads, allowing them to trigger Ghostscript processing in a shared temporary directory. An attacker can exploit a race condition during GnuPG configuration to inject and execute arbitrary Python code with the privileges of the application process.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the underlying server, leading to a complete compromise of the SysReptor platform. Given the platform's role in storing sensitive pentest reporting data, this could result in unauthorized access to highly confidential client information and potential lateral movement within the network. The CVSS score of 8.8 reflects the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Upgrade to SysReptor Professional version 2026.61 or later immediately to apply the necessary security fixes.
Proactive Monitoring: Review application logs for unusual file upload activity or unexpected worker service restarts, which may indicate exploitation attempts.
Compensating Controls: Restrict image upload functionality to trusted users only and ensure the application environment is hardened to prevent unauthorized access to temporary directories.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant security risk for SysReptor Professional deployments due to the potential for arbitrary code execution. Organizations are strongly advised to verify their current version and update to 2026.61 immediately. Failure to patch may expose the organization to total system compromise and the exfiltration of sensitive penetration testing documentation.
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
- https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wmf3-gv8j-7qp7
- https://github.com/Syslifters/sysreptor/commit/7d800e5c737df0dbc3d4ea2d095c89235790a1cc
- https://github.com/Syslifters/sysreptor/commit/7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea
- https://github.com/Syslifters/sysreptor/commit/e8bd31cb42a15a10bb5102337b55dde704be397f
- https://github.com/Syslifters/sysreptor/commit/f27760961943fb1716cbb68f2a6705e7251b4e5c
- https://github.com/Syslifters/sysreptor/commit/f5ad35b9e71d370b5e06ef4680979cb05c24ff3c
- https://github.com/Syslifters/sysreptor/releases/tag/2026.61