Code Execution Vulnerability in Notepad++ Affecting WinGup Functionality
CVE-2026-57233

8.1HIGH

Key Information:

Vendor
CVE Published:
17 August 2026

What is CVE-2026-57233?

Notepad++ is a popular open-source source code editor. A security flaw prior to version 8.9.7 in the WinGup decompress function allows an attacker to overwrite DLL files in sibling plugin directories by exploiting untrusted ZIP entry names. This vulnerability poses a significant risk as it could lead to the execution of malicious code when the affected plugin loads next. The issue was resolved in the 8.9.7 release, highlighting the importance of strong validation and containment when handling file paths.

Affected Version(s)

notepad-plus-plus < 8.9.7

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.