Notepad++ Zero-Click RCE via Path Traversal (CVE-2026-52884)
A zero-click remote code execution vulnerability (CVE-2026-52884) has been identified in Notepad++ v8.9.6.1 due to improper path traversal validation. The flaw allows attackers to execute arbitrary code by bypassing security checks in the application's command execution function.
Why it matters
This represents a significant security risk for users of a widely used text editor, potentially allowing for system compromise without user interaction.
notepad-plus-plus / notepad-plus-plus Public Notifications You must be signed in to change notification settings Fork 5.3k Star 28.3k Code Issues 2.9k Pull requests 19 Actions Projects Wiki Security and quality 13 Insights Additional navigation options Code Issues Pull requests Actions Projects Wiki Security and quality Insights notepad-plus-plus Security Advisories GHSA-p58x-r3c9-x9p6 CVE-2026-48800 Bypass High donho published GHSA-p58x-r3c9-x9p6 May 31, 2026 Package No package listed Affected versions v8.9.6.1 Patched versions v8.9.6.2 Description Vulnerability Summary Product : Notepad++ v8.9.6.1 (latest patched version) Type : CWE-42 (Path Traversal) / CWE-59 (Improper Link Resolution) Impact : Arbitrary Code Execution without user confirmation CVSS 3.1 : 7.8 (High) — AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Bypasses : CVE-2026-48800 (shortcuts.xml command validation)
The content is a technical security advisory based on factual vulnerability data.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in