Path Manipulation Vulnerability in SumatraPDF Reader
CVE-2026-107732

8.4HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107732?

SumatraPDF, a versatile document reader for Windows, suffers from a path manipulation vulnerability in versions 3.6.1 and earlier. The issue arises when untrusted document paths and PDF link targets are included in notification text, which is processed by the ParseTip() function as trusted markup. This flaw can be exploited when a user clicks on an injected link, triggering the ExecuteTipLink() function, which may lead to the execution of arbitrary commands in the user's context through the CmdExec command. This security concern does not claim any broader implications beyond the supported advisory conditions, and no fixed version has been issued at this time.

Affected Version(s)

sumatrapdf <= 3.6.1

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.