PowerShell Command Injection Vulnerability in Notepad++ Installer
CVE-2026-73250

5.4MEDIUM

Key Information:

Vendor
CVE Published:
11 August 2026

What is CVE-2026-73250?

Notepad++ is a widely used open-source source code editor that, in its versions prior to 8.9.7, allows an attacker to influence the installation directory variable $INSTDIR. This vulnerability enables the execution of commands in the security context of the installer when the context menu component is selected. Specifically, the $() subexpression syntax can be exploited, leading to potential unauthorized command execution during installation. The issue has been resolved in version 8.9.7, and users are advised to upgrade to this version to mitigate the risk.

Affected Version(s)

notepad-plus-plus < 8.9.7

References

CVSS V4

Score:
5.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.