SysReptor is a fully customizable pentest reporting platform. Prior to 2026.61, authenticated users of SysReptor Professional can upload image files whose formats cause image processing to invoke Ghostscript, allowing embedded PostScript to operate in the shared temporary directory. An attacker can combine that behavior with a race involving GnuPG configuration files in temporary subdirectories to cause GnuPG to copy attacker-controlled Python code into the application code directory. The injected code executes with the privileges of the SysReptor application process after a worker restart. The Community edition is not affected. Version 2026.58 contains a partial mitigation, and this issue is fully fixed in version 2026.61.
https://github.com/Syslifters/sysreptor/security/advisories/GHSA-wmf3-gv8j-7qp7
https://github.com/Syslifters/sysreptor/releases/tag/2026.61
https://github.com/Syslifters/sysreptor/commit/f5ad35b9e71d370b5e06ef4680979cb05c24ff3c
https://github.com/Syslifters/sysreptor/commit/f27760961943fb1716cbb68f2a6705e7251b4e5c
https://github.com/Syslifters/sysreptor/commit/e8bd31cb42a15a10bb5102337b55dde704be397f
https://github.com/Syslifters/sysreptor/commit/7ecf56a6b8e5c05a2d2212bc8aa340f69855cdea
https://github.com/Syslifters/sysreptor/commit/7d800e5c737df0dbc3d4ea2d095c89235790a1cc