7.8
CVE-2026-77605
- EPSS 0.19%
- Veröffentlicht 22.09.2026 17:13:21
- Zuletzt bearbeitet 28.09.2026 18:17:25
- Erkennungen
Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file. This issue is fixed in version 8.9.8.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Herstellernotepad-plus-plus
≫
Produkt
notepad-plus-plus
Version
< 8.9.8
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.19% | 0.085 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-706 Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.
https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-w5xq-frjg-w4cw
https://github.com/notepad-plus-plus/notepad-plus-plus/commit/00fa5df0da1d4f6b334317aa979db13ac77ee24d
https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.8
https://notepad-plus-plus.org/news/v898-released