CVE-2026-77605
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
22/09/2026
Last modified:
23/09/2026
Description
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file. This issue is fixed in version 8.9.8.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
References to Advisories, Solutions, and Tools
- https://github.com/notepad-plus-plus/notepad-plus-plus/commit/00fa5df0da1d4f6b334317aa979db13ac77ee24d
- https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.8
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-w5xq-frjg-w4cw
- https://notepad-plus-plus.org/news/v898-released


