PT-2026-44400 · Notepad++ · Notepad++

·

CVE-2026-48778

·

Published

2026-05-26

·

Updated

2026-06-29

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.6.1
Description An issue exists in the processing of the commandLineInterpreter parameter within the config.xml configuration file. The software fails to neutralize special elements, which allows an attacker to replace cmd.exe with malicious executables via unvalidated config.xml files, leading to arbitrary code execution on the victim's machine.
Recommendations Update to version 8.9.6.1.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-07493
CVE-2026-48778
GHSA-7HM3-WP5Q-CCV9

Affected Products

Notepad++