CVE-2026-25926 describes an Unsafe Search Path vulnerability (CWE-426) in Notepad++ versions prior to 8.9.2. This flaw allows for the potential execution of a malicious explorer.exe if an attacker can manipulate the process's working directory when Windows Explorer is launched without an absolute path. The vulnerability carries a CVSS v3.1 score of 7.3 (HIGH), indicating a local attack vector with low complexity, requiring user interaction, and potentially leading to high impact on confidentiality, integrity, and availability. This could result in arbitrary code execution in the context of the running Notepad++ application. Currently, there is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, with no mentions or articles reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 8.9.2CPE matchmatch criteria | cpe:2.3:a:notepad-plus-plus:notepad\+\+:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.