Information disclosure in Notepad++ - #VU144998
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to exposure of sensitive information to an unauthorized actor in the clickable link handling feature when processing a user-clicked file:// link in an opened document. A remote attacker can provide a specially crafted text file containing a file:// link to disclose sensitive information.
User interaction is required to click the crafted link, and the issue occurs in the default configuration on Windows.