๐Ÿ” CVE Alert

CVE-2026-107802

UNKNOWN 0.0

SumatraPDF โ€” Windows command-line argument injection in AI selection-translate

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, src/SelectionTranslate.cpp embeds selected or pasted translation text in quoted Windows command lines using incomplete quote-only escaping. The affected BuildGrokTranslateCmdLineTemp(), BuildClaudeTranslateCmdLineTemp(), and BuildCodexTranslateCmdLineTemp() functions can allow attacker-controlled text to inject model, working-directory, approval, or sandbox-bypass flags when the corresponding agentic CLI backend is installed and used. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CWE CWE-88
Vendor sumatrapdfreader
Product sumatrapdf
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for sumatrapdfreader sumatrapdf

Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sumatrapdfreader / sumatrapdf
<= 3.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-xvxg-cwmx-hr7j github.com: https://github.com/sumatrapdfreader/sumatrapdf/commit/6b88a751ab34a28bafca3bdd635aaa2f4c1e06b6