OS Command Injection in Notepad++ - CVE-2026-48778
Published: May 26, 2026
Notepad++
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to command injection in the config.xml commandLineInterpreter handling when opening the containing folder in cmd. A remote attacker can supply a crafted config.xml value to execute arbitrary code.
User interaction is required to trigger the File → Open Containing Folder → cmd action.