Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.
CVSS Details
- CVSS 4.0 Base Score: 8.4 (HIGH)
- CVSS 4.0 Vector: (CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade evince-develUpgrade evince-browser-pluginUpgrade evince-nautilusUpgrade evince-previewerUpgrade evinceUpgrade evince-libsUpgrade evince-thumbnailer | Jun 25, 2026 | Jun 24, 2026 |
| Alpine Linux | — | Upgrade evinceUpgrade atril | Jun 18, 2026 | Jun 10, 2026 |
| Amazon Linux Ami 2 | — | Upgrade evince-browser-pluginUpgrade evince-libsUpgrade evince-nautilusUpgrade evince-debuginfoUpgrade evinceUpgrade evince-dviUpgrade evince-devel | Jun 23, 2026 | Jun 23, 2026 |
| Amazon_linux_2023 | — | Upgrade papers-previewerUpgrade papers-libs-debuginfoUpgrade papers-thumbnailerUpgrade papers-nautilusUpgrade papers-debugsourceUpgrade papers-nautilus-debuginfoUpgrade papers-libsUpgrade papers-debuginfoUpgrade papers-previewer-debuginfoUpgrade papers-develUpgrade papersUpgrade papers-thumbnailer-debuginfo | Jun 15, 2026 | Jun 10, 2026 |
| Debian | — | Upgrade evinceUpgrade atril | May 24, 2026 | May 24, 2026 |
| Redhat_linux | — | Upgrade evince-previewerUpgrade evince-thumbnailer-debuginfoUpgrade evince-thumbnailerUpgrade evince-previewer-debuginfoUpgrade evince-libsUpgrade evince-dviUpgrade evince-nautilus-debuginfoUpgrade evince-nautilusUpgrade evince-debugsourceNo solution existsUpgrade evinceUpgrade evince-debuginfoUpgrade evince-develUpgrade evince-libs-debuginfoUpgrade evince-dvi-debuginfoUpgrade evince-browser-plugin-debuginfoUpgrade evince-browser-plugin | Jun 24, 2026 | Jun 10, 2026 |
| Rocky_linux | — | Upgrade evince-thumbnailer-debuginfoUpgrade evince-libs-debuginfoUpgrade evince-browser-plugin-debuginfoUpgrade evinceUpgrade evince-nautilus-debuginfoUpgrade evince-develUpgrade evince-thumbnailerUpgrade evince-debuginfoUpgrade evince-nautilusUpgrade evince-previewer-debuginfoUpgrade evince-libsUpgrade evince-debugsourceUpgrade evince-previewerUpgrade evince-browser-plugin | Jun 29, 2026 | Jun 25, 2026 |
| Ubuntu | — | Upgrade evince-commonUpgrade papersUpgrade evince | May 25, 2026 | May 22, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub