CVE-2026-107732: Sumatrapdfreader Sumatrapdf
High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, untrusted document paths and PDF link targets are interpolated into notification text that ParseTip() interprets as trusted tip markup. When a user clicks an injected link, ExecuteTipLink() dispatches its CmdExec command and can execute an attacker-selected local program in the user's context. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Affected products
- Sumatrapdfreader Sumatrapdf: up to and including 3.6.1
Published 2026-10-08. Last modified 2026-10-08.