# Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection, Stack Buffer Overflow, and Zip Slip Path Traversal (CVE-2026-52886, CVE-2026-54758, CVE-2026-57233)

> Notepad++ v8.9.6.4 and earlier contain five distinct vulnerabilities patched in v8.9.7: a session.xml backupFilePath path-validation bypass (CVE-2026-52886), a stack buffer overflow in expandNppEnvironmentStrs (CVE-2026-54758, CVSS 7.8), a Zip Slip path traversal in the WinGUp plugin updater (CVE-2026-57233), a shortcuts.xml macro HMAC-validation bypass (GHSA-f4rj-vqq4-wvg4, CVE pending), and an installer-time PowerShell command injection via unsanitized installation path interpolation (GHSA-gp2r-262h-9hgf, CVE pending). None are known to be actively exploited; exploitation requires local file write access, a tampered plugin package, a malicious installation path, or a crafted shortcuts.xml/session.xml.

- **Published:** 2026-07-15T00:00:00Z
- **Last reviewed:** 2026-07-15T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1348
- **ID:** TL-2026-1348
- **Severity:** MEDIUM (CVSS 7.8)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 15 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-52886, CVE-2026-54758, CVE-2026-57233

## Description

On 2026-07-14 the Notepad++ project shipped v8.9.7, closing out five separate security issues discovered across the editor's configuration handling, environment-variable expansion, plugin update mechanism, macro engine, and NSIS installer. CVE-2026-52886 (GHSA-rqfm-pw34-r7j6) is a path-validation bypass in session restoration: Notepad++ validates the backupFilePath attribute of session.xml using a raw std::wstring::starts_with() prefix check against the backup directory, with no path normalization. An attacker who can write session.xml (trivial in portable installs) can craft a path such as '[backup_dir].....\\Windows\\System32\\drivers\\etc\\hosts' that passes the prefix check but resolves via OS path traversal to files outside the backup directory, exposing SSH keys, environment files, and credential stores as editor tabs on next launch with snapshot/session restore enabled. CVE-2026-54758 (GHSA-gv94-327x-2gc5, CVSS 3.1 7.8, AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, CWE-121/CWE-787) is a stack-based buffer overflow in the expandNppEnvironmentStrs function in RunDlg.cpp: variable names referenced in the Run dialog (e.g. via $(LONG_VARIABLE_NAME)) are copied into a fixed MAX_PATH (260-byte) stack buffer without bounds checking the copy loop index, so an environment variable name of 260+ characters overflows adjacent stack memory. In practice this is caught by MSVC /GS stack-canary protection and crashes the process (denial of service); code execution would require stack protection to be absent or bypassed. CVE-2026-57233 (GHSA-hjxw-84rf-wg5r, CWE-22) is a Zip Slip path-traversal flaw in WinGUp's plugin-package decompress() routine: the extractor does not verify that extracted entries remain inside the target plugin directory, so a crafted plugin ZIP containing an entry named e.g. '../mimeTools/mimeTools.dll' extracts outside its intended folder and overwrites a DLL belonging to a sibling, legitimate plugin, which is then loaded (and executed) by Notepad++ or that plugin on next use. GHSA-f4rj-vqq4-wvg4 documents an incomplete fix to a prior shortcuts.xml integrity control: HMAC/tamper validation was added for UserDefinedCommands but never extended to Macros (CWE-78/CWE-345/CWE-693), so a macro loaded from an attacker-controlled shortcuts.xml can invoke Scintilla actions and internal Notepad++ menu commands (including 'Open in Default Viewer' against an attacker-chosen executable) without triggering the same validation, enabling conditional elevated command execution when a privileged Notepad++ instance consumes an attacker-influenced settings directory. GHSA-gp2r-262h-9hgf documents install-time PowerShell command injection in the NSIS installer: the installer builds an MSIX context-menu registration command as 'Add-AppxPackage -Path "$INSTDIR\\contextMenu\\NppShell.msix" -ExternalLocation "$INSTDIR\\contextMenu\\"' with $INSTDIR interpolated directly inside a double-quoted PowerShell string; an attacker who controls the chosen installation directory (e.g. 'C:\\Users\\Public\\npp-$(calc)') can inject PowerShell subexpression syntax that is expanded and executed during the MSIX registration step on Windows 11 x64/ARM64 installs with the default context-menu component selected. All five issues were fixed in v8.9.7, released the same day the fixes were disclosed; none appear in the CISA KEV catalog and no PoC is known to be exploited in the wild, consistent with the hunt rationale's assessment of local/social-engineering-only attack vectors. This disclosure follows a prior, unrelated 2025 incident in which a suspected Chinese state-sponsored actor compromised Notepad++'s shared-hosting infrastructure (June 2025-December 2025) to redirect update traffic before the project migrated hosting and hardened WinGUp signature verification; that incident is background context only and is not attributed to these five 2026 CVEs.

## MITRE ATT&CK

- T1608.001 Upload Malware
- T1195 Supply Chain Compromise
- T1195.002 Compromise Software Supply Chain
- T1204 User Execution
- T1059.001 PowerShell
- T1203 Exploitation for Client Execution
- T1554 Compromise Host Software Binary
- T1068 Exploitation for Privilege Escalation
- T1574.001 DLL
- T1553.002 Code Signing
- T1036 Masquerading
- T1574 Hijack Execution Flow
- T1552.001 Credentials In Files
- T1005 Data from Local System
- T1499 Endpoint Denial of Service

## Sources

- [Multiple Notepad++ Vulnerabilities Enable PowerShell Command Injection Attacks](https://cybersecuritynews.com/notepad-vulnerabilities-command-injection/)
- [Notepad++ v8.9.7 - Slava Ukraini (release notes)](https://notepad-plus-plus.org/news/v897-slava-ukraini/)
- [Download Notepad++ v8.9.7 - Slava Ukraini](https://notepad-plus-plus.org/downloads/v8.9.7/)
- [Notepad++ release 8.9.7 (community forum thread)](https://community.notepad-plus-plus.org/topic/27604/notepad-release-8.9.7)
- [GHSA-rqfm-pw34-r7j6: session.xml backupFilePath starts_with Bypass (CVE-2026-52886)](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-rqfm-pw34-r7j6)
- [GHSA-gv94-327x-2gc5: Stack Buffer Overflow in expandNppEnvironmentStrs (CVE-2026-54758)](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gv94-327x-2gc5)
- [GHSA-hjxw-84rf-wg5r: WinGup Zip Slip Path Traversal (CVE-2026-57233)](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-hjxw-84rf-wg5r)
- [GHSA-f4rj-vqq4-wvg4: shortcuts.xml Macro HMAC Bypass Enables Conditional Elevated Command Execution](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-f4rj-vqq4-wvg4)
- [GHSA-gp2r-262h-9hgf: Install-time PowerShell command injection through installation path](https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-gp2r-262h-9hgf)
- [Notepad++ vulnerabilities could enable arbitrary code execution on Windows systems](https://www.csoonline.com/article/4178622/notepad-vulnerabilities-could-enable-arbitrary-code-execution-on-windows-systems.html)
- [Important Clarification: Notepad++ Security Incident (2025 update-hijack background)](https://notepad-plus-plus.org/news/clarification-security-incident/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1348
