CVE-2026-107733
SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, FrameOnCommand() handles CmdExec by passing a null current-tab pointer to RunWithExe(), which dereferences WindowTab::filePath. A local process in the same interactive Windows session, at an integrity level greater than or equal to SumatraPDF's under Windows UIPI, can dispatch CmdExec over DDE or WM_COPYDATA while no document tab is open, causing abrupt process termination and loss of unsaved state. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
| CWE | CWE-476 |
| Vendor | sumatrapdfreader |
| Product | sumatrapdf |
| Published | Oct 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for sumatrapdfreader sumatrapdf
Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
sumatrapdfreader / sumatrapdf
<= 3.6.1