Information disclosure in Notepad++ - #VU144991

 

Information disclosure in Notepad++ - #VU144991

Published: August 24, 2026


Vulnerability identifier: #VU144991
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to exposure of sensitive information to an unauthorized actor in workspace path handling and custom toolbar path processing when parsing a crafted workspace file or loading a crafted toolbar configuration. A remote attacker can supply UNC paths that trigger automatic path probes to disclose sensitive information.

User interaction is required to open the crafted workspace for the primary attack path.


Affected software

Notepad++

Remediation

Install security update from vendor's website.

Notepad++ - update to 8.9.8

External References

Related Security Bulletins