Command Injection Vulnerability in Multi-Format Reader for Windows by SumatraPDF
CVE-2026-107734
7.1HIGH
What is CVE-2026-107734?
SumatraPDF, a widely used multi-format reader for Windows, presents a vulnerability that allows attackers to craft malicious .synctex.gz files. When a user opens a PDF and triggers an inverse search, the application passes an attacker-controlled SyncTeX source filename directly into an external editor command line without ensuring secure argument quoting. This lack of proper validation can lead to command-line flags being injected, potentially resulting in unauthorized actions or even arbitrary code execution through the external editor. The severity of the impact varies depending on how the targeted editor handles these malicious flags. Currently, there is no fixed version available to mitigate this issue.
Affected Version(s)
sumatrapdf <= 3.5.2
