What happened
Verified via NVD REST API (published 2026-10-08): in SumatraPDF <= 3.6.1, BuildGrokTranslateCmdLineTemp()/BuildClaudeTranslateCmdLineTemp()/BuildCodexTranslateCmdLineTemp() embed translation text in quoted Windows command lines with incomplete quote-only escaping. Attacker-controlled text can inject model, working-directory, approval or sandbox-bypass flags into the corresponding AI coding-agent CLI (CWE-88). CISA SSVC marks exploitation at PoC/technical-impact total.
Why it matters
This is an injection path into AI coding agents (Grok/Claude/Codex) reachable from a common PDF reader — an attacker-supplied document can manipulate the agent CLI's model selection, working directory, approval gating or sandbox settings, an agent-config tampering primitive in a developer-adjacent tool.
Attack vector
Selected or pasted text containing crafted quotes is embedded in quoted Windows command lines for translation backends with incomplete quote-only escaping (CWE-88); attacker-controlled text injects model, working-directory, approval, or sandbox-bypass flags into the AI agent CLI invocation.
Affected systems
SumatraPDF <= 3.6.1 on Windows, when the Grok, Claude, or Codex agentic CLI backend is installed and used for translation
Mitigation
No fixed SumatraPDF version yet as of 2026-10-09; advised to avoid using the agentic-CLI translate backends on untrusted selected text and to monitor the GHSA for the fix: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-xvxg-cwmx-hr7j