Stack-based buffer overflow in Notepad++ - #VU144997
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to stack-based buffer overflow in NppParameters::writeSession when processing an overlong session path from the -settingsDir command-line option during session backup creation. A remote attacker can supply a specially crafted settings directory path and trigger application exit to cause a denial of service.
User interaction is required to launch Notepad++ with the crafted command-line argument.