Information disclosure in Notepad++ - #VU144991
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in workspace path handling and custom toolbar path processing when parsing a crafted workspace file or loading a crafted toolbar configuration. A remote attacker can supply UNC paths that trigger automatic path probes to disclose sensitive information.
User interaction is required to open the crafted workspace for the primary attack path.