← Vulnerability feed

Vulnerability record · CVE-2025-27837 · published 25 March 2025

CVE-2025-27837: Artifex ghostscript path traversal vulnerability

Artifex · Ghostscript

An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

9.8 CVSS 3.1 Critical EPSS 0.61% · top 53.2% CWE-22 · Path traversal
9.8CVSS 3.1 base score
0.61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

An issue was discovered in Artifex Ghostscript before 10.05.0. Access to arbitrary files can occur through a truncated path with invalid UTF-8 characters, for base/gp_mswin.c and base/winrtsup.cpp.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27837 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2017-8291Ghostscript -dSAFER bypass and command execution via type confusionGhostscript through 2017-04-26 contains a type confusion in .rsdparams handling that lets a crafted .eps document bypass the -dSAFER sandbox. A "/Out…KEVEPSS 97%analysed9.9CVE-2021-3781Ghostscript -dSAFER sandbox escape via crafted pipe commandGhostscript's -dSAFER sandbox can be escaped by injecting a specially crafted pipe command, allowing a malicious document to run arbitrary commands a…EPSS 84%analysed9.8CVE-2025-27836Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The BJ10V device has a Print buffer overflow in contrib/japanese/gdev10v.c.EPSS 0.59%9.8CVE-2025-27831Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The DOCXWRITE TXTWRITE device has a text buffer overflow via long characters to device…EPSS 0.59%9.8CVE-2025-27832Artifex ghostscript classic buffer overflow vulnerabilityAn issue was discovered in Artifex Ghostscript before 10.05.0. The NPDL device has a Compression buffer overflow for contrib/japanese/gdevnpdl.c.EPSS 0.82%9.8CVE-2020-36773Artifex ghostscript use after free vulnerabilityArtifex Ghostscript before 9.53.0 has an out-of-bounds write and use-after-free in devices/vector/gdevtxtw.c (for txtwrite) because a single characte…EPSS 0.88%9.8CVE-2023-28879Artifex ghostscript out-of-bounds write vulnerabilityIn Artifex Ghostscript through 10.01.0, there is a buffer overflow leading to potential corruption of data internal to the PostScript interpreter, in…EPSS 6.3%9.8CVE-2020-15900Artifex ghostscript out-of-bounds write vulnerabilityA memory corruption issue was found in Artifex Ghostscript 9.50 and 9.52. Use of a non-standard PostScript operator can allow overriding of file acce…EPSS 5.2%

Source: NIST National Vulnerability Database (record CVE-2025-27837), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.