Threat reportVulnerabilityTL-2026-1348
Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)
Multiple Notepad++ Vulnerabilities Enable PowerShell Command (TL-2026-1348), also tracked as session.xml backupFilePath starts_with Bypass, is a medium-severity software vulnerability scored CVSS 7.8, first published 2026-07-15. It has no confirmed attribution, affects Notepad++ (Don Ho) Notepad++, references 3 CVEs (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233), maps to 15 MITRE ATT&CK techniques (T1005, T1036, T1059.001), and is covered by 9 detection rules and 15 indicators of compromise.
- CVSS
- 7.8/10Medium
- CVEs
- 3Referenced vulnerabilities
- Techniques
- 15MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 15Indicators of compromise
Key facts for TL-2026-1348
- Threat ID
- TL-2026-1348
- Also known as
- session.xml backupFilePath starts_with Bypass, expandNppEnvironmentStrs Stack Buffer Overflow, WinGUp Zip Slip, shortcuts.xml Macro HMAC Bypass, NSIS Installer PowerShell Command Injection
- Severity
- MEDIUM
- CVSS
- 7.8 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- information-technology, software-development, government administration, finance, health, education, general-enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 15
Malware and tooling in Multiple Notepad++ Vulnerabilities Enable PowerShell Command
Malware and tooling: WinGup
How Multiple Notepad++ Vulnerabilities Enable PowerShell Command works
Notepad++ v8.9.6.4 and earlier contain five distinct vulnerabilities patched in v8.9.7: a session.xml backupFilePath path-validation bypass (CVE-2026-52886), a stack buffer overflow in expandNppEnvironmentStrs (CVE-2026-54758, CVSS 7.8), a Zip Slip path traversal in the WinGUp plugin updater (CVE-2026-57233), a shortcuts.xml macro HMAC-validation bypass (GHSA-f4rj-vqq4-wvg4, CVE pending), and an installer-time PowerShell command injection via unsanitized installation path interpolation (GHSA-gp2r-262h-9hgf, CVE pending). None are known to be actively exploited; exploitation requires local file write access, a tampered plugin package, a malicious installation path, or a crafted shortcuts.xml/session.xml.
On 2026-07-14 the Notepad++ project shipped v8.9.7, closing out five separate security issues discovered across the editor's configuration handling, environment-variable expansion, plugin update mechanism, macro engine, and NSIS installer. CVE-2026-52886 (GHSA-rqfm-pw34-r7j6) is a path-validation bypass in session restoration: Notepad++ validates the backupFilePath attribute of session.xml using a raw std::wstring::starts_with() prefix check against the backup directory, with no path normalization. An attacker who can write session.xml (trivial in portable installs) can craft a path such as '[backup_dir].....\\Windows\\System32\\drivers\\etc\\hosts' that passes the prefix check but resolves via OS path traversal to files outside the backup directory, exposing SSH keys, environment files, and credential stores as editor tabs on next launch with snapshot/session restore enabled. CVE-2026-54758 (GHSA-gv94-327x-2gc5, CVSS 3.1 7.8, AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, CWE-121/CWE-787) is a stack-based buffer overflow in the expandNppEnvironmentStrs function in RunDlg.cpp: variable names referenced in the Run dialog (e.g. via $(LONG_VARIABLE_NAME)) are copied into a fixed MAX_PATH (260-byte) stack buffer without bounds checking the copy loop index, so an environment variable name of 260+ characters overflows adjacent stack memory. In practice this is caught by MSVC /GS stack-canary protection and crashes the process (denial of service); code execution would require stack protection to be absent or bypassed. CVE-2026-57233 (GHSA-hjxw-84rf-wg5r, CWE-22) is a Zip Slip path-traversal flaw in WinGUp's plugin-package decompress() routine: the extractor does not verify that extracted entries remain inside the target plugin directory, so a crafted plugin ZIP containing an entry named e.g. '../mimeTools/mimeTools.dll' extracts outside its intended folder and overwrites a DLL belonging to a sibling, legitimate plugin, which is then loaded (and executed) by Notepad++ or that plugin on next use. GHSA-f4rj-vqq4-wvg4 documents an incomplete fix to a prior shortcuts.xml integrity control: HMAC/tamper validation was added for UserDefinedCommands but never extended to Macros (CWE-78/CWE-345/CWE-693), so a macro loaded from an attacker-controlled shortcuts.xml can invoke Scintilla actions and internal Notepad++ menu commands (including 'Open in Default Viewer' against an attacker-chosen executable) without triggering the same validation, enabling conditional elevated command execution when a privileged Notepad++ instance consumes an attacker-influenced settings directory. GHSA-gp2r-262h-9hgf documents install-time PowerShell command injection in the NSIS installer: the installer builds an MSIX context-menu registration command as 'Add-AppxPackage -Path "$INSTDIR\\contextMenu\\NppShell.msix" -ExternalLocation "$INSTDIR\\contextMenu\\"' with $INSTDIR interpolated directly inside a double-quoted PowerShell string; an attacker who controls the chosen installation directory (e.g. 'C:\\Users\\Public\\npp-$(calc)') can inject PowerShell subexpression syntax that is expanded and executed during the MSIX registration step on Windows 11 x64/ARM64 installs with the default context-menu component selected. All five issues were fixed in v8.9.7, released the same day the fixes were disclosed; none appear in the CISA KEV catalog and no PoC is known to be exploited in the wild, consistent with the hunt rationale's assessment of local/social-engineering-only attack vectors. This disclosure follows a prior, unrelated 2025 incident in which a suspected Chinese state-sponsored actor compromised Notepad++'s shared-hosting infrastructure (June 2025-December 2025) to redirect update traffic before the project migrated hosting and hardened WinGUp signature verification; that incident is background context only and is not attributed to these five 2026 CVEs.
MITRE ATT&CK techniques used in TL-2026-1348
Collection
Defense Evasion
T1036 Masquerading; T1574 Hijack Execution Flow
Execution
T1059.001 PowerShell; T1203 Exploitation for Client Execution; T1204 User Execution
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Initial Access
T1195 Supply Chain Compromise; T1195.002 Compromise Software Supply Chain
Impact
T1499 Endpoint Denial of Service
Credential Access
T1552.001 Credentials In Files
defense-impairment
Persistence
T1554 Compromise Host Software Binary
stealth
Resource Development
Affected products and versions in Multiple Notepad++ Vulnerabilities Enable PowerShell Command
- Notepad++ (Don Ho) — Notepad++
Vulnerable versions: <= 8.9.6.4
Fixed in: 8.9.7 - Notepad++ (Don Ho) — WinGUp (Notepad++ auto-updater)
Vulnerable versions: <= 8.9.6.4
Fixed in: 8.9.7 - Notepad++ (Don Ho) — Notepad++ NSIS Installer
Vulnerable versions: <= 8.9.6.4
Fixed in: 8.9.7
Remediation for Multiple Notepad++ Vulnerabilities Enable PowerShell Command
Patches
- Notepad++ v8.9.7 (2026-07-14) - fixes CVE-2026-52886, CVE-2026-54758, CVE-2026-57233, GHSA-f4rj-vqq4-wvg4, GHSA-gp2r-262h-9hgf
Immediate actions
- Upgrade all Notepad++ installations to v8.9.7 or later
- Re-download Notepad++ manually from notepad-plus-plus.org rather than relying on in-app auto-update until the update chain is verified
- Restrict write access to session.xml, shortcuts.xml, and the Notepad++ settings/config directory, especially on portable/shared installations
- Disable session/snapshot auto-restore on shared or multi-user Windows systems until patched
- Avoid installing Notepad++ into attacker-influenceable or user-writable installation paths; do not accept custom install paths from untrusted sources
- Verify the integrity/signature of any Notepad++ plugin package before installation; do not install plugins from unofficial sources
Workarounds
- Do not restore Notepad++ sessions from untrusted or shared session.xml files
- Do not load shortcuts.xml or macros from untrusted sources
- Manually verify installation directory names do not contain PowerShell subexpression syntax ($(...)) before running the NSIS installer
Longer-term hardening
- Enforce application allowlisting/code-signing verification for editor plugins and extensions in enterprise environments
- Monitor for unexpected PowerShell child processes spawned by installer/setup binaries (Add-AppxPackage invocations from non-standard paths)
- Apply least-privilege principles to text-editor installs; avoid running Notepad++ elevated as a matter of routine
- Include developer-tool auto-update channels (WinGUp and similar) in software supply-chain risk assessments
CVEs associated with Multiple Notepad++ Vulnerabilities Enable PowerShell Command
CVE-2026-52886, CVE-2026-54758, CVE-2026-57233
Weaknesses (CWE) in Multiple Notepad++ Vulnerabilities Enable PowerShell Command
Timeline of Multiple Notepad++ Vulnerabilities Enable PowerShell Command
- Background context (unrelated to the 2026 CVEs): a suspected Chinese state-sponsored actor compromises Notepad++'s shared-hosting infrastructure and begins redirecting update traffic.
- Notepad++ project completes hosting migration and hardening, closing the 2025 update-hijack incident; WinGUp signature verification enforcement follows in subsequent releases.
- CSOonline previews a related but distinct set of Notepad++ configuration-file vulnerabilities (CVE-2026-48770, CVE-2026-48778, CVE-2026-48800), highlighting a pattern of unchecked input handling in Notepad++ config files.
- Fix for the NSIS installer PowerShell command injection (GHSA-gp2r-262h-9hgf), reported by researcher P4P3R (@P4P3R-HAK), lands in commit 3764d5b ahead of the v8.9.7 release.
- v8.9.7 additionally fixes the shortcuts.xml macro HMAC bypass (GHSA-f4rj-vqq4-wvg4) and the NSIS installer PowerShell command injection via unsanitized $INSTDIR interpolation (GHSA-gp2r-262h-9hgf); both remain without assigned CVE IDs at release time.
- GitHub Security Advisories GHSA-rqfm-pw34-r7j6, GHSA-gv94-327x-2gc5, GHSA-hjxw-84rf-wg5r, GHSA-f4rj-vqq4-wvg4, and GHSA-gp2r-262h-9hgf published concurrently with the v8.9.7 release.
- Notepad++ v8.9.7 ('Slava Ukraini') released, patching CVE-2026-52886 (session.xml path bypass), CVE-2026-54758 (expandNppEnvironmentStrs stack buffer overflow), and CVE-2026-57233 (WinGUp Zip Slip).
- Cyber Security News publishes coverage summarizing all five patched vulnerabilities, framing them as PowerShell command injection, memory corruption, and path traversal risks.
Sources cited for Multiple Notepad++ Vulnerabilities Enable PowerShell Command
- Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks
- Notepad++ v8.9.7 - Slava Ukraini (release notes)
- Download Notepad++ v8.9.7 - Slava Ukraini
- Notepad++ release 8.9.7 (community forum thread)
- GHSA-rqfm-pw34-r7j6: session.xml backupFilePath starts_with Bypass (CVE-2026-52886)
- GHSA-gv94-327x-2gc5: Stack Buffer Overflow in expandNppEnvironmentStrs (CVE-2026-54758)
- GHSA-hjxw-84rf-wg5r: WinGup Zip Slip Path Traversal (CVE-2026-57233)
- GHSA-f4rj-vqq4-wvg4: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution
- GHSA-gp2r-262h-9hgf: Install-time PowerShell command injection through installation path
- Notepad++ vulnerabilities could enable arbitrary code execution on Windows systems
- Important Clarification: Notepad++ Security Incident (2025 update-hijack background)
Detection coverage for TL-2026-1348
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1348 across Splunk SPL, Microsoft KQL and Sigma, covering 15 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.