PT-2026-27008 · Flos · Notepad2

Haehanse

+1

·

Published

2026-03-22

·

Updated

2026-04-30

·

CVE-2026-4546

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flos Freeware Notepad2 version 4.2.25
Description A weakness exists in Flos Freeware Notepad2 4.2.25, impacting an unknown function within the TextShaping.dll library. Exploitation involves a manipulation that can lead to an uncontrolled search path. The attack is limited to local execution and is considered difficult to exploit, requiring a high level of complexity. The vendor was contacted regarding this issue but did not respond.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Uncontrolled Search Path Element

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2026-4546

Affected Products

Notepad2