๐Ÿ” CVE Alert

CVE-2026-107734

UNKNOWN 0.0

SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the resulting command line is passed to CreateProcessW(). A user with an external editor configured or auto-detected who opens a PDF with a crafted .synctex.gz file and invokes inverse search can inject command-line flags; the resulting impact depends on the target editor interpreting those flags and can include unintended editor actions or code execution through a malicious extension. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CWE CWE-20 CWE-88
Vendor sumatrapdfreader
Product sumatrapdf
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for sumatrapdfreader sumatrapdf

Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sumatrapdfreader / sumatrapdf
<= 3.5.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-jf4v-rw66-j4w2 github.com: https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b