CVE-2026-107732EPSS p2.3%
CVE-2026-107732CVE-2026-107732
Description
SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, untrusted document paths and PDF link targets are interpolated into notification text that ParseTip() interprets as trusted tip markup. When a user clicks an injected link, ExecuteTipLink() dispatches its CmdExec command and can execute an attacker-selected local program in the user's context. No broader impact is claimed beyond the advisory-supported conditions. No fixed version is available as of this review.
Scoring
| EPSS | 0.13% probability of exploitation · percentile 2.3% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-08 |