Path traversal in Notepad++ - #VU144993
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to delete or overwrite files outside the intended backup directory.
The vulnerability exists due to path traversal in session.xml backupFilePath handling when loading a supplied session file and later processing backup file paths during save or close operations. A local user can place a crafted session.xml in the Notepad++ settings directory to delete or overwrite files outside the intended backup directory.
User interaction is required to open Notepad++ and save or close the restored document, and the delete target must already exist.