OS Command Injection in Notepad++ - #VU144985

 

OS Command Injection in Notepad++ - #VU144985

Published: August 24, 2026


Vulnerability identifier: #VU144985
CSH Severity: Medium
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to execute arbitrary code.

The vulnerability exists due to command injection in the MSI installer RunOnce PowerShell command when processing a crafted INSTALLFOLDER value or MSI transform during installation. A local user can supply a specially crafted installation path to execute arbitrary code.

User interaction is required because an administrator must perform the crafted installation, and the injected code runs at the next logon in the logging-on user\'s RunOnce context rather than automatically as SYSTEM.


Affected software

Notepad++

Remediation

Install security update from vendor's website.

Notepad++ - update to 8.9.8

External References

Related Security Bulletins