CVE-2026-107734
Deferred Deferred - Pending Action

Command Injection in SumatraPDF via SyncTeX Filename

Vulnerability report for CVE-2026-107734, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the resulting command line is passed to CreateProcessW(). A user with an external editor configured or auto-detected who opens a PDF with a crafted .synctex.gz file and invokes inverse search can inject command-line flags; the resulting impact depends on the target editor interpreting those flags and can include unintended editor actions or code execution through a malicious extension. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.5.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-88 The product constructs a string for a command to be executed by a separate component in another control sphere, but it does not properly delimit the intended arguments, options, or switches within that command string.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF versions 3.5.2 and earlier have a vulnerability where an attacker can craft a SyncTeX filename that injects malicious command-line arguments into an external editor when using inverse search. This happens because the filename replaces the %f placeholder without proper Windows argument quoting, allowing command injection through the editor's command line.

Detection Guidance

This vulnerability requires SumatraPDF with an external editor configured and a crafted .synctex.gz file. Check SumatraPDF settings for external editor paths and inspect PDFs for suspicious .synctex.gz files. No direct detection commands are provided in the context.

Impact Analysis

If you use SumatraPDF with an external editor and open a PDF containing a malicious .synctex.gz file, an attacker could execute arbitrary commands on your system through the editor. This could lead to unintended actions or full code execution, depending on the editor's behavior.

Compliance Impact

This vulnerability does not directly impact compliance with GDPR or HIPAA as it requires specific user actions (opening a crafted PDF and invoking inverse search) and depends on the external editor's behavior. No broader impact beyond the described conditions is claimed.

Mitigation Strategies

Disable or remove the external editor feature in SumatraPDF until a patch is available. Avoid opening PDF files from untrusted sources, especially those with .synctex.gz files.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107734. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart