SumatraPDF 是一款适用于 Windows 的多格式文档阅读器。在版本 3.6.1 及更早版本中, 在将选定或粘贴的翻译文本嵌入带引号的 Windows 命令行时,仅使用了不完整的引号转义机制。受影响函数 、 和 允许攻击者注入由用户控制的文本,从而在已安装并使用的相应代理式命令行接口(CLI)后端中注入模型参数、工作目录参数、审批标志或绕过沙箱的标志。除漏洞公告所述的条件外,未声称存在更广泛的影响。截至本次审查时,尚无修复版本可用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| sumatrapdfreader | sumatrapdf | <= 3.6.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107732 | 8.4 HIGH | SumatraPDF: Markup/command-link injection into UI notification text |
| CVE-2026-107734 | 7.1 HIGH | SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Executi |
| CVE-2026-107733 | 6.8 MEDIUM | SumatraPDF: Null-pointer dereference in `CmdExec` when no document tab is open |
| CVE-2026-107736 | 6.8 MEDIUM | SumatraPDF: stack buffer overflow while processing EXIF Orientation metadata |
| CVE-2026-107738 | 6.8 MEDIUM | SumatraPDF: Untrusted binary record offset used without lower-bound validation |
| CVE-2026-107737 | 5.7 MEDIUM | SumatraPDF CHM `its://` signed index causes an out-of-bounds object lookup |
| CVE-2026-107731 | 5.5 MEDIUM | SumatraPDF: LIT parser range-validation flaws cause invalid-pointer reads and denial of se |
| CVE-2026-107729 | 5.5 MEDIUM | SumatraPDF: Unsigned-to-signed hdrLen validation bypass in SumatraPDF MOBI parsing causes |
| CVE-2026-107730 | 5.5 MEDIUM | SumatraPDF: Signed integer overflow in the LIT header parsing causes invalid-pointer read |
| CVE-2026-107735 | 5.4 MEDIUM | SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initia |
No comments yet