PT-2026-38552 · Unknown · Notepadnext

Dohyun4455

·

Published

2026-05-07

·

Updated

2026-05-12

·

CVE-2026-42214

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad Next versions prior to 0.14
Description The detectLanguageFromExtension() function interpolates a file extension directly into a Lua script without sanitization. An attacker can craft a filename with an extension containing Lua code that executes automatically when the file is opened. Since luaL openlibs() is called unconditionally, the injected code has access to the full os, io, and package libraries, allowing for arbitrary command execution.
Recommendations Update to version 0.14.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-42214

Affected Products

Notepadnext