CVE-2026-107732: Sumatrapdfreader Sumatrapdf

High severity, CVSS 8.4. EPSS: 0.1% chance of exploitation in the next 30 days.

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, untrusted document paths and PDF link targets are interpolated into notification text that ParseTip() interprets as trusted tip markup. When a user clicks an injected link, ExecuteTipLink() dispatches its CmdExec command and can execute an attacker-selected local program in the user's context. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

Affected products

Published 2026-10-08. Last modified 2026-10-08.