PT-2026-58887 · Notepad++ · Notepad++

CVE-2026-54758

·

Published

2026-07-15

·

Updated

2026-09-12

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Notepad++ versions prior to 8.9.7
Description The expandNppEnvironmentStrs() function in PowerEditor/src/WinControls/StaticDialog/RunDlg/RunDlg.cpp copies a variable name located between $( and ) into a fixed-size wchar t str[MAX PATH] stack buffer. Because the m loop index is not bounded, a variable name containing 260 or more characters can corrupt adjacent stack data. This can lead to process termination via report gsfailure or potential arbitrary code execution.
Recommendations Update to version 8.9.7.

Exploit

Fix

RCE

Memory Corruption

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54758
GHSA-GV94-327X-2GC5

Affected Products

Notepad++