Command Line Injection Vulnerability in SumatraPDF Reader
CVE-2026-107802
7.1HIGH
What is CVE-2026-107802?
A command line injection vulnerability exists in SumatraPDF, a multi-format reader for Windows. In versions 3.6.1 and earlier, the application fails to properly escape commands in quoted Windows command lines when embedding selected or pasted translation text. Functions such as BuildGrokTranslateCmdLineTemp(), BuildClaudeTranslateCmdLineTemp(), and BuildCodexTranslateCmdLineTemp() allow attacker-controlled text to be injected, potentially leading to unauthorized command execution when certain CLI backends are utilized. As of the latest review, no fix has been issued for this issue.
Affected Version(s)
sumatrapdf <= 3.6.1
