CVE-2026-107734

Source
https://cve.org/CVERecord?id=CVE-2026-107734
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107734.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107734
Aliases
  • GHSA-jf4v-rw66-j4w2
Published
2026-10-08T22:24:23Z
Modified
2026-10-10T07:06:08Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
SumatraPDF: SyncTeX Argument Injection in Inverse Search Enables Arbitrary Command Execution via External Editors
Details

SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, an attacker-controlled SyncTeX source filename is substituted for the %f placeholder in an external editor command line without safe Windows argument quoting, and the resulting command line is passed to CreateProcessW(). A user with an external editor configured or auto-detected who opens a PDF with a crafted .synctex.gz file and invokes inverse search can inject command-line flags; the resulting impact depends on the target editor interpreting those flags and can include unintended editor actions or code execution through a malicious extension. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-20",
        "CWE-88"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107734.json"
}
References

Affected packages

Git / github.com/sumatrapdfreader/sumatrapdf

Affected ranges

Type
GIT
Repo
https://github.com/sumatrapdfreader/sumatrapdf
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "3.5.2"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.4split
1.5split
1.6split
1.7split
1.8split
1.9split
2.*
2.0split
2.1split
2.2split
2.3split
2.4split
2.5split
3.*
3.0split
3.1.2rel
3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107734.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "function_hash": "147797068263823284444083557914968976149",
            "length": 1507
        },
        "id": "CVE-2026-107734-449bc743",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
        "target": {
            "file": "src/PdfSync.cpp",
            "function": "SyncTex::DocToSource"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "109078092724637545305918608770041504877",
                "9723967613718875422450415522211503058",
                "297757323087969418225642511780247625550"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107734-595a91d4",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
        "target": {
            "file": "src/PdfSync.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "330636242127463871983943305599795381265",
                "283526657395119306978053621298685280560",
                "304141964553518509944822793882847195102",
                "339996138859842490783719240813369641211"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-107734-9b81c0f6",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
        "target": {
            "file": "src/SearchAndDDE.cpp"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "279007402742875351443035413393742303869",
            "length": 894
        },
        "id": "CVE-2026-107734-a4362e3e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/sumatrapdfreader/sumatrapdf/commit/398d23624362c60722d9709173a287ea53545b3b",
        "target": {
            "file": "src/SearchAndDDE.cpp",
            "function": "BuildOpenFileCmdTemp"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:06:08Z"