Input validation error in Notepad++ - #VU151934
Published: September 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose NetNTLMv2 challenge-response hashes.
The vulnerability exists due to improper UNC path validation in the isUncPath and isUncFileUrl helpers when processing crafted UNC paths or file URLs. A remote attacker can supply path or URL variations that Windows resolves to an attacker-controlled SMB share to disclose NetNTLMv2 challenge-response hashes.
User interaction is required to open a crafted session, project, or configuration file, or to activate a recognized link.