Command Line Injection Vulnerability in SumatraPDF Reader
CVE-2026-107802

7.1HIGH

Key Information:

Vendor
CVE Published:
8 October 2026

What is CVE-2026-107802?

A command line injection vulnerability exists in SumatraPDF, a multi-format reader for Windows. In versions 3.6.1 and earlier, the application fails to properly escape commands in quoted Windows command lines when embedding selected or pasted translation text. Functions such as BuildGrokTranslateCmdLineTemp(), BuildClaudeTranslateCmdLineTemp(), and BuildCodexTranslateCmdLineTemp() allow attacker-controlled text to be injected, potentially leading to unauthorized command execution when certain CLI backends are utilized. As of the latest review, no fix has been issued for this issue.

Affected Version(s)

sumatrapdf <= 3.6.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.