notepad++是notepad++个人开发者开源的一款轻量级的代码与文本编辑工具。 Notepad++ 8.9.7之前版本存在安全漏洞,该漏洞源于从攻击者控制的shortcuts.xml加载的宏绕过UserDefinedCommands的HMAC验证,并可调用Scintilla操作和内部Open in Default Viewer命令,当本地攻击者影响settingsDir且用户触发宏时,可能导致修改受保护文件并在特定条件下执行提升权限的命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-57233 | 8.1 HIGH | Notepad++: Path Traversal (Zip Slip) in WinGup Plugin Extraction |
| CVE-2026-54758 | 7.8 HIGH | Notepad++: Stack Buffer Overflow in expandNppEnvironmentStrs |
| CVE-2026-52886 | 5.1 MEDIUM | Notepad++: session.xml backupFilePath starts_with Bypass |
No comments yet