Vulnerability  ·  2026-10-10

SumatraPDF agentic-CLI translate commands inject model/sandbox-bypass flags into Grok/Claude/Codex backends (CVSS 7.1)

VulnerabilityHigh impactGlobalCVE-2026-107802
Verified via NVD REST API (published 2026-10-08): in SumatraPDF <= 3.6.1, BuildGrokTranslateCmdLineTemp()/BuildClaudeTranslateCmdLineTemp()/BuildCodexTranslateCmdLineTemp() embed translation text in quoted Windows command lines with incomplete quote-only escaping. Attacker-controlled text can inject model, working-directory, approval or sandbox-bypass flags into the corresponding AI coding-agent CLI (CWE-88). CISA SSVC marks exploitation at PoC/technical-impact total.
This is an injection path into AI coding agents (Grok/Claude/Codex) reachable from a common PDF reader — an attacker-supplied document can manipulate the agent CLI's model selection, working directory, approval gating or sandbox settings, an agent-config tampering primitive in a developer-adjacent tool.
Selected or pasted text containing crafted quotes is embedded in quoted Windows command lines for translation backends with incomplete quote-only escaping (CWE-88); attacker-controlled text injects model, working-directory, approval, or sandbox-bypass flags into the AI agent CLI invocation.
SumatraPDF <= 3.6.1 on Windows, when the Grok, Claude, or Codex agentic CLI backend is installed and used for translation
No fixed SumatraPDF version yet as of 2026-10-09; advised to avoid using the agentic-CLI translate backends on untrusted selected text and to monitor the GHSA for the fix: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-xvxg-cwmx-hr7j
NVD CVE-2026-107802GitHub Security Advisory
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →