notepad++是notepad++个人开发者开源的一款轻量级的代码与文本编辑工具。 Notepad++ 8.9.7之前版本存在路径遍历漏洞,该漏洞源于对session.xml中backupFilePath属性验证时未进行路径规范化,可能导致在快照模式恢复期间通过父目录序列读取备份目录之外的任意用户可读文件。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57233 | 8.1 HIGH | Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction |
| CVE-2026-54758 | 7.8 HIGH | Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs |
| CVE-2026-71858 | 5.4 MEDIUM | Notepad++: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution |
No comments yet