WeSearch

POC for CVE-2026-46529 – RCE via PDF argv injection

·4 min read · 0 reactions · 0 comments · 20 views
#cybersecurity#vulnerability#exploit
POC for CVE-2026-46529 – RCE via PDF argv injection
TL;DR · WeSearch summary

A new proof-of-concept exploit has been developed for a vulnerability (CVE-2026-46529) in PDF viewers like atril and evince. This exploit allows arbitrary code execution through a crafted PDF file by utilizing argv injection techniques. The attack can be executed simply by clicking anywhere on the rendered PDF page, making it particularly dangerous for users.

Key facts
Original article
GitHub
Read full at GitHub →
Opening excerpt (first ~120 words) tap to expand

RCE via PDF argv injection (CVE-2026-46529) (atril/xreader/evince) Working proof-of-concept for the argv injection in ev_spawn() (shell/ev-application.c). A single click anywhere on the rendered page of a crafted PDF triggers arbitrary code execution as the user running the viewer. This release uses the %f-substitution technique: the dlopen target path is discovered by the viewer itself at runtime, so the attacker needs zero knowledge of where the polyglot lands on the victim's filesystem (no username, no $HOME, no download directory). POC Screen.Recording.2026-05-15.at.02.28.19.mp4 What's in this bundle File Purpose exploit.sh One-shot wrapper: compile + build polyglot in a single command. evil_gtk_module.c Source of the payload.

Excerpt limited to ~120 words for fair-use compliance. The full article is at GitHub.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from GitHub