---
id: CVE-2026-81180
title: SysReptor is a fully customizable pentest reporting platform
summary: >-
  SysReptor is a fully customizable pentest reporting platform. Prior to
  2026.61, authenticated users of SysReptor Professional can upload image files
  whose formats cause image processing to invoke Ghostscript, allowing embedded
  PostScript…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-20
vendor: Syslifters
product: sysreptor
affected:
  - sysreptor < 2026.61
published: '2026-09-18'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:18:02.227'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81180'
references:
  - url: >-
      https://github.com/Syslifters/sysreptor/commit/7d800e5c737df0dbc3d4ea2d095c89235790a1cc
    label: security-advisories@github.com
  - url: >-
      https://github.com/Syslifters/sysreptor/commit/7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea
    label: security-advisories@github.com
  - url: >-
      https://github.com/Syslifters/sysreptor/commit/e8bd31cb42a15a10bb5102337b55dde704be397f
    label: security-advisories@github.com
  - url: >-
      https://github.com/Syslifters/sysreptor/commit/f27760961943fb1716cbb68f2a6705e7251b4e5c
    label: security-advisories@github.com
  - url: >-
      https://github.com/Syslifters/sysreptor/commit/f5ad35b9e71d370b5e06ef4680979cb05c24ff3c
    label: security-advisories@github.com
  - url: 'https://github.com/Syslifters/sysreptor/releases/tag/2026.61'
    label: security-advisories@github.com
  - url: >-
      https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wmf3-gv8j-7qp7
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
epss: 0.00663
epssPercentile: 0.49578
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T15:15:18.561499Z'
ingestedAt: '2026-09-18T18:47:53.265Z'
---

## Overview

SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to cause GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor application process after a worker restart. The Community edition is not affected. Version 2026.58 contains a partial mitigation, and this issue is fully fixed in version 2026.61.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
