Command Injection Vulnerability in Multi-Format Reader for Windows by SumatraPDF
CVE-2026-107734

7.1HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107734?

SumatraPDF, a widely used multi-format reader for Windows, presents a vulnerability that allows attackers to craft malicious .synctex.gz files. When a user opens a PDF and triggers an inverse search, the application passes an attacker-controlled SyncTeX source filename directly into an external editor command line without ensuring secure argument quoting. This lack of proper validation can lead to command-line flags being injected, potentially resulting in unauthorized actions or even arbitrary code execution through the external editor. The severity of the impact varies depending on how the targeted editor handles these malicious flags. Currently, there is no fixed version available to mitigate this issue.

Affected Version(s)

sumatrapdf <= 3.5.2

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.