MEDIUM
Notepad++: session.xml backupFilePath starts_with Bypass
Published Aug 17, 2026
5.1
MEDIUMCVSS 4.0
EPSS 0.17%
Description
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::wstring::starts_with against the expected backup directory without path normalization, allowing parent-directory sequences during snapshot-mode restoration to read an arbitrary user-readable file outside the backup directory into an editor tab. This issue is fixed in version 8.9.7.
Affected products
-
- Version < 8.9.7StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Notepad-Plus-Plus | Notepad-Plus-Plus | n/a |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60374 Advisory
- https://github.com/notepad-plus-plus/notepad-plus-plus/commit/7e66f36db666a13b09fb5c31232ab2ca1c2ebccc x_refsource_MISC
- https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.7 x_refsource_MISC
- https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-rqfm-pw34-r7j6 exploitx_refsource_CONFIRM
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-60374 | Advisory | |
| https://github.com/notepad-plus-plus/notepad-plus-plus/commit/7e66f36db666a13b09fb5c31232ab2ca1c2ebccc | x_refsource_MISC | |
| https://github.com/notepad-plus-plus/notepad-plus-plus/releases/tag/v8.9.7 | x_refsource_MISC | |
| https://github.com/notepad-plus-plus/notepad-plus-plus/security/advisories/GHSA-rqfm-pw34-r7j6 | exploitx_refsource_CONFIRM |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 17, 2026
Updated Aug 18, 2026
Reserved Jun 8, 2026
Link CVE-2026-52886
CISA Vulnrichment
Updated Aug 18, 2026
ENISA EUVD
EUVD-2026-60374 Assigner GitHub_M
Published Aug 17, 2026
Updated Aug 18, 2026
Exploited since n/a
Link EUVD-2026-60374