PT-2026-70941 · Notepad++ · Notepad++
CVE-2026-73250
·
Published
2026-08-11
·
Updated
2026-08-13
CVSS v4.0
5.4
Medium
| Vector | AV:L/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Notepad++ versions prior to 8.9.7
Description
The Windows 11 x64 and ARM64 installer for this source code editor contains a command injection flaw. The installer passes the installation directory variable
$INSTDIR from PowerEditor/installer/nppSetup.nsi into a PowerShell -Command string used by RegisterMSIX to invoke Add-AppxPackage. When the context menu component is selected, an attacker can use PowerShell subexpression syntax, such as $(), within the installation path to execute arbitrary commands in the security context of the installer.Recommendations
Update to version 8.9.7.
Exploit
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Notepad++