Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107734— SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors

Quick assessment

Affected
sumatrapdfreader sumatrapdf
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

SumatraPDF 是 Windows 平台上的多格式文档阅读器。在版本 3.5.2 及更早版本中,攻击者可控的 SyncTeX 源文件名会被直接替换到外部编辑器命令行中的 占位符处,且未采用安全的 Windows 参数引号转义方式。最终构造的命令行被传递给 函数执行。当用户已配置或自动检测到外部编辑器,并打开一个包含精心构造的 文件的 PDF 文档并触发反向搜索功能时,攻击者可在命令行中注入额外参数。该漏洞的实际影响取决于目标编辑器对这些参数的解析行为,可能导致非预期的编辑器操作,或通过恶意扩展实现代码执行。除

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107734

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors
Source: CVE Program / CVE List V5
Vulnerability Description
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the resulting command line is passed to CreateProcessW(). A user with an external editor configured or auto-detected who opens a PDF with a crafted .synctex.gz file and invokes inverse search can inject command-line flags; the resulting impact depends on the target editor interpreting those flags and can include unintended editor actions or code execution through a malicious extension. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
输入验证不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
sumatrapdfreader sumatrapdf <= 3.5.2 -

II. Public POCs for CVE-2026-107734

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107734

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-107734 (1)

Vendor Advisories for CVE-2026-107734 (1)

Same Patch Batch · sumatrapdfreader · 2026-10-08 · 11 CVEs total

CVE-2026-107732 8.4 HIGH SumatraPDF: Markup/command-link injection into UI notification text
CVE-2026-107802 7.1 HIGH SumatraPDF — Windows command-line argument injection in AI selection-translate
CVE-2026-107733 6.8 MEDIUM SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open
CVE-2026-107736 6.8 MEDIUM SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata
CVE-2026-107738 6.8 MEDIUM SumatraPDF: Untrusted binary record offset used without lower-bound validation
CVE-2026-107737 5.7 MEDIUM SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup
CVE-2026-107731 5.5 MEDIUM SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se
CVE-2026-107729 5.5 MEDIUM SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes
CVE-2026-107730 5.5 MEDIUM SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read
CVE-2026-107735 5.4 MEDIUM SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia

IV. Related Vulnerabilities

V. Comments for CVE-2026-107734

No comments yet


Leave a comment