MajorCritical vulnerability
CVE-2026-107732 (CVSS 8.4)
NVD · officialPublished Oct 8, 2026Risk 37/100
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, untrusted document paths and PDF link targets are interpolated into notification text that ParseTip() interprets as trusted tip markup. When a user clicks an injected link, ExecuteTipLink() dispatches its CmdExec command and can execute an attacker-selected local program in the user's context. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Technical details
CVSS
8.4
AV:LocalAC:LowPR:NoneUI:Active
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source