Path Manipulation Vulnerability in SumatraPDF Reader
CVE-2026-107732
8.4HIGH
What is CVE-2026-107732?
SumatraPDF, a versatile document reader for Windows, suffers from a path manipulation vulnerability in versions 3.6.1 and earlier. The issue arises when untrusted document paths and PDF link targets are included in notification text, which is processed by the ParseTip() function as trusted markup. This flaw can be exploited when a user clicks on an injected link, triggering the ExecuteTipLink() function, which may lead to the execution of arbitrary commands in the user's context through the CmdExec command. This security concern does not claim any broader implications beyond the supported advisory conditions, and no fixed version has been issued at this time.
Affected Version(s)
sumatrapdf <= 3.6.1
