SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the resulting command line is passed to CreateProcessW(). A user with an external editor configured or auto-detected who opens a PDF with a crafted .synctex.gz file and invokes inverse search can inject command-line flags; the resulting impact depends on the target editor interpreting those flags and can include unintended editor actions or code execution through a malicious extension. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-20",
"CWE-88"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107734.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"last_affected": "3.5.2"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107734.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "147797068263823284444083557914968976149",
"length": 1507
},
"id": "CVE-2026-107734-449bc743",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
"target": {
"file": "src/PdfSync.cpp",
"function": "SyncTex::DocToSource"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"109078092724637545305918608770041504877",
"9723967613718875422450415522211503058",
"297757323087969418225642511780247625550"
],
"threshold": 0.9
},
"id": "CVE-2026-107734-595a91d4",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
"target": {
"file": "src/PdfSync.cpp"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"330636242127463871983943305599795381265",
"283526657395119306978053621298685280560",
"304141964553518509944822793882847195102",
"339996138859842490783719240813369641211"
],
"threshold": 0.9
},
"id": "CVE-2026-107734-9b81c0f6",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
"target": {
"file": "src/SearchAndDDE.cpp"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "279007402742875351443035413393742303869",
"length": 894
},
"id": "CVE-2026-107734-a4362e3e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
"target": {
"file": "src/SearchAndDDE.cpp",
"function": "BuildOpenFileCmdTemp"
}
}
]
"2026-10-10T07:06:08Z"