๐Ÿ” CVE Alert

CVE-2026-107732

UNKNOWN 0.0

SumatraPDF: Markup/command-link injection into UI notification text

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, untrusted document paths and PDF link targets are interpolated into notification text that ParseTip() interprets as trusted tip markup. When a user clicks an injected link, ExecuteTipLink() dispatches its CmdExec command and can execute an attacker-selected local program in the user's context. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CWE CWE-94
Vendor sumatrapdfreader
Product sumatrapdf
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for sumatrapdfreader sumatrapdf

Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sumatrapdfreader / sumatrapdf
<= 3.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-2wv2-qm2f-vmxh github.com: https://github.com/sumatrapdfreader/sumatrapdf/commit/8b680387ed69e3504ef296e09d6e032f81076af8