Use of Incorrectly-Resolved Name or Reference in Notepad++ - CVE-2026-77605
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to use of incorrectly-resolved name or reference in the \"Run by system\" feature when handling a user-selected .txt file that has a sibling .txt.cmd file in the same directory. A remote attacker can place a crafted sibling .txt.cmd file and trick the victim into triggering \"Run by system\" on the .txt file to execute arbitrary commands.
User interaction is required to trigger the vulnerable action.