CVE-2026-101258
Received Received - Intake

Ghostscript PostScript Sandbox Escape via Memory Corruption

Vulnerability report for CVE-2026-101258, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: redhat-SADP

Description

A flaw was found in Ghostscript. When Ghostscript renders a crafted PostScript or EPS document, it can bypass the -dSAFER sandbox and execute arbitrary shell commands in the context of the Ghostscript process. The issue chains memory corruption in document parsing with disabling of internal path access controls at runtime. An attacker can deliver the document directly or through formats that delegate rendering to Ghostscript (for example EPS import or print conversion workflows). Successful exploitation can compromise confidentiality, integrity, and availability of data accessible to the process running Ghostscript.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
artifex ghostscript *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-787 The product writes data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Ghostscript allows an attacker to bypass the -dSAFER sandbox and execute arbitrary shell commands through a crafted PostScript or EPS document. It combines memory corruption during document parsing with disabled path access controls, enabling full system compromise.

Detection Guidance

Detection involves checking for Ghostscript versions vulnerable to PostScript/EPS document parsing flaws. Inspect installed versions with commands like 'gs --version' or 'dpkg -l | grep ghostscript' on Debian-based systems. Monitor for unusual process activity or shell command execution during document rendering.

Impact Analysis

If exploited, this flaw could allow attackers to access sensitive data, modify files, or disrupt services running on the same system as Ghostscript. Users opening malicious documents could unknowingly trigger command execution.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's confidentiality requirements and HIPAA's safeguards for protected health information. Organizations using Ghostscript may face compliance violations if exploited.

Mitigation Strategies

Immediately update Ghostscript to the latest patched version. Disable EPS import or print conversion workflows if possible. Restrict user permissions to limit impact of potential exploitation. Monitor for suspicious document processing activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101258. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart