PowerShell Command Injection Vulnerability in Notepad++ Installer
CVE-2026-73250
5.4MEDIUM
What is CVE-2026-73250?
Notepad++ is a widely used open-source source code editor that, in its versions prior to 8.9.7, allows an attacker to influence the installation directory variable $INSTDIR. This vulnerability enables the execution of commands in the security context of the installer when the context menu component is selected. Specifically, the $() subexpression syntax can be exploited, leading to potential unauthorized command execution during installation. The issue has been resolved in version 8.9.7, and users are advised to upgrade to this version to mitigate the risk.
Affected Version(s)
notepad-plus-plus < 8.9.7
