Ubuntu Security Notices USN-8321-1 USN-8321-1: Papers vulnerability Publication date 27 May 2026 Overview Papers could be made to run programs as your login if it opened a specially crafted PDF file. Releases 26.04 LTS 25.10 Open side navigation Close side navigation Packages Details Update instructions References Related notices Packages papers - PDF document viewer for GNOME Details It was discovered that Papers incorrectly handled PDF /GoToR actions. If a user were tricked into opening a specially crafted PDF file, an attacker could use this issue to manipulate command lines and possibly execute arbitrary code. It was discovered that Papers incorrectly handled PDF /GoToR actions. If a user were tricked into opening a specially crafted PDF file, an attacker could use this issue to manipulate command lines and possibly execute arbitrary code. Update instructions In general, a standard system update will make all the necessary changes. Learn more about how to get the fixes. The problem can be corrected by updating your system to the following package versions: Ubuntu Release Package Version 26.04 LTS resolute papers – 50.1-0ubuntu1.1 25.10 questing papers – 48.0-1ubuntu1.25.10.4 Reduce your security exposure Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines. Get Ubuntu Pro References CVE-2026-46529 CVE-2026-46529 Related notices USN-8295-1 USN-8295-1
A vulnerability (CVE-2026-46529) in the Papers PDF viewer for GNOME allows arbitrary code execution via command line manipulation when a user opens a malicious PDF file containing a specially crafted /GoToR action. The flaw affects Papers packages for Ubuntu 26.04 LTS and 25.10, which are fixed by updating to version 50.1-0ubuntu1.1 for Ubuntu 26.04 LTS and version 48.0-1ubuntu1.25.10.4 for Ubuntu 25.10. A standard system update will apply the necessary patches.