CVE-2026-5525 is a stack-based buffer overflow vulnerability in Notepad++ version 8.9.3 affecting the file drop handler component. The vulnerability occurs when users drag and drop directory paths of exactly 259 characters without a trailing backslash, causing the application to append a backslash and null terminator without proper bounds checking. The flaw results in application crashes due to stack buffer overrun conditions. The vulnerability carries a CVSS 3.1 score of 6.0 (MEDIUM) with a local attack vector requiring user interaction and low privilege access. Exploitation demands relatively high complexity and specific conditions, yet successful exploitation could result in high confidentiality and integrity impacts. The EPSS probability score of 0.00011 indicates very low likelihood of real-world exploitation compared to other vulnerabilities. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from the Known Exploited Vulnerabilities catalog and inactive on threat intelligence hot lists. No publicly available exploit code has been documented, and community attention remains minimal. Organizations should prioritize patching based on environmental risk rather than immediate exploitation threats, though the specific conditions required to trigger the overflow remain relatively narrow in typical user workflows.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
8.9.3CPE matchmatch criteria | cpe:2.3:a:notepad-plus-plus:notepad\+\+:8.9.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.