CVE-2026-25880: Untrusted Search Path in SumatraPDF Reader (explorer.exe on Windows)
SumatraPDF is a multi-format reader for Windows. In 3.5.2 and earlier, the PDF reader allows execution of a malicious binary (explorer.exe) located in the same directory as the opened PDF when the user clicks File → “Show in folder”. This behavior leads to arbitrary code execution on the victim’s system with the privileges of the current user, without any warning or user interaction beyond the menu click.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25880?
CVE-2026-25880 has a moderate severity rating due to its potential to execute malicious binaries.
How do I fix CVE-2026-25880?
To fix CVE-2026-25880, update SumatraPDF to version 3.5.3 or later, where the vulnerability has been addressed.
What platforms are affected by CVE-2026-25880?
CVE-2026-25880 affects the SumatraPDF reader on Windows systems.
Can CVE-2026-25880 lead to remote code execution?
Yes, CVE-2026-25880 can lead to remote code execution if a user interacts with a malicious PDF file.
What versions of SumatraPDF are impacted by CVE-2026-25880?
CVE-2026-25880 impacts versions of SumatraPDF up to and including 3.5.2.