External Control of File Name or Path in Notepad++ - #VU144999

 

External Control of File Name or Path in Notepad++ - #VU144999

Published: August 24, 2026


Vulnerability identifier: #VU144999
CSH Severity: Medium
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to external control of file name or path in the session file parser when processing crafted session files containing UNC paths. A remote attacker can trick the victim into opening a crafted session file to disclose sensitive information.

User interaction is required to open the crafted session file, and exploitation on Windows causes automatic SMB authentication to an attacker-controlled server.


Affected software

Notepad++

Remediation

Install security update from vendor's website.

Notepad++ - update to 8.9.6.1

External References

Related Security Bulletins