CVE-2026-46529: PDF /GoToR action argv injection enables single-click RCE via --gtk-module dlopen
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is shell/ev-application.c:evspawn, which builds a command line from attacker-controlled PDF link-destination fields without applying gshellquote. The cmdline is then handed to gappinfocreatefromcommandline, which shell-parses it back into argv — splitting any embedded --gtk-module=PATH into a separate argv element. GTK then dlopen()s the path during init, running any attribute((constructor)) it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT --checkpoint-action injection in comics-document.c, fixed in 1.6.2) but in a different code path (shell/ev-application.c) that the original patch did not touch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/atrilto a version that resolves this vulnerability.Fixed in 1.24.0-1+deb11u2Fixed in 1.28.4-1 - Upgrade
Upgrade
debian/evinceto a version that resolves this vulnerability.Fixed in 3.38.2-1+deb11u1Fixed in 43.1-2+deb12u1Fixed in 48.1-3+deb13u1Fixed in 49~alpha.1-1 - Upgrade
Upgrade
debian/evince-gtk3to a version that resolves this vulnerability.Fixed in 48.4+dfsg-1 - Upgrade
Upgrade
debian/papersto a version that resolves this vulnerability.Fixed in 49.3-3 - Upgrade
Upgrade
Atril (Evince fork) / Evince/Atril/Xaderto a version that resolves this vulnerability.Fixed in 1.26.3 - Upgrade
Upgrade
Atril (Evince fork) / Evince/Atril/Xaderto a version that resolves this vulnerability.Fixed in 1.28.4 - Compensating control
To mitigate single-click RCE from malicious PDFs, block or filter opening of untrusted PDF documents in Atril/Evince (e.g., via mail/document gateway controls or local policy) until Atril is upgraded to 1.26.3 or 1.28.4.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-46529?
The severity of CVE-2026-46529 is rated at 25.
How do I fix CVE-2026-46529?
To fix CVE-2026-46529, update to the latest version of Evince, Atril, or Xader that addresses this vulnerability.
What software is affected by CVE-2026-46529?
CVE-2026-46529 affects Gnome Evince, MATE Atril, Xader, and specific Debian packages related to these applications.
What type of vulnerability is CVE-2026-46529?
CVE-2026-46529 is classified as a command injection vulnerability.
When was CVE-2026-46529 published?
CVE-2026-46529 was published on May 19, 2026.