Skip to content
Threat Feed
high advisory

Ghostscript Sandbox Escape via Crafted PostScript Files

A sandbox bypass vulnerability in Ghostscript allows attackers to achieve arbitrary command execution by rendering malicious PostScript or EPS documents that circumvent the -dSAFER protection.

CVE search metadata

CVE search record: CVE-2026-101258. Severity: high. CVSS: 7.8. KEV: no. Product: Ghostscript. Brief: Ghostscript Sandbox Escape via Crafted PostScript Files. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ghostscript-sandbox-bypass/

CVE-2026-101258 describes a critical security flaw in the Ghostscript rendering engine that enables an attacker to bypass the -dSAFER sandbox. The vulnerability stems from a combination of memory corruption within the document parsing engine and the ability to programmatically disable internal path access controls at runtime. By supplying a specially crafted PostScript or EPS file to a service or application that utilizes Ghostscript for rendering, an attacker can escalate privileges from the document parsing stage to arbitrary code execution within the security context of the Ghostscript process. This issue poses a significant risk to enterprise document conversion workflows, print spoolers, and automated processing pipelines that handle external document inputs.

Impact

Successful exploitation of this vulnerability results in arbitrary command execution on the host system. Depending on the privileges assigned to the service performing the rendering, this can lead to full system compromise, exfiltration of sensitive documents, or lateral movement within the network. Sectors heavily reliant on automated document processing, such as legal, financial, and government services, are at the highest risk.

Recommendation

Prioritize the identification of all internal systems and applications that leverage Ghostscript for file processing or conversion tasks. Ensure that these environments are updated immediately once a patch is released by Artifex Software. Monitor for instances of Ghostscript processes initiating unexpected child processes, as this is a primary indicator of successful sandbox escape and command execution.


Immediate actions

Inventory all systems using Ghostscript for document processing or rendering services.

IT Operations 48h

Mitigations

Monitor for unexpected child processes spawned by Ghostscript or gs instances.

immediate Security Operations

CVE-2026-101258