漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Notepad++: CVE-2026-48800 Bypass
Vulnerability Description
Notepad++ is a free and open-source source code editor. In v8.9.6.1, isInTrustedDirectory() does NOT canonicalize the path before checking. It uses a prefix-based check (PathIsPrefix() or equivalent) that matches paths starting with trusted directory strings. A path traversal using ..\..\ after a trusted directory prefix passes the check while resolving to an untrusted location. The CVE-2026-48800 patch adds isInTrustedDirectory() validation in Command::run() (RunDlg.cpp) before calling ShellExecute(). This function checks whether the resolved executable path is under a trusted directory. This vulnerability is fixed in 8.9.6.2.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vulnerability Type
路径等价:’filename.’ (尾部点号)
Vulnerability Title
notepad++ 路径遍历漏洞
Vulnerability Description
notepad++是notepad++个人开发者开源的一款文本编辑器软件。 notepad++ 8.9.6.1版本存在路径遍历漏洞,该漏洞源于路径规范化问题,当检查路径前未进行标准化处理,使用基于前缀的检查方式,导致路径遍历攻击。
CVSS Information
N/A
Vulnerability Type
N/A