Insufficient verification of data authenticity in Notepad++ - #VU144995
Published: August 24, 2026
Vulnerability details
The vulnerability allows a local user to execute arbitrary commands.
The vulnerability exists due to insufficient verification of data authenticity in the shortcuts.xml macro playback path when running a tampered macro through the \"Run a Macro Multiple Times\" dialog. A local user can supply a crafted shortcuts.xml macro and trigger it through the dialog to execute arbitrary commands.
User interaction is required to run the macro through the dialog.