← Back to CVE List
Vulnerability Intelligence Report
Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)

CVE-2026-77605

Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file. This issue is fixed in version 8.9.8.

No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-20 ↗CWE-20: Improper Input Validation
CWE-706 ↗CWE-706: Use of Incorrectly-Resolved Name or Reference

Affected Products & Versions

Vendor Product Affected Versions
notepad-plus-plus notepad-plus-plus < 8.9.8 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-08-20T20:48:20
Published2026-09-22T17:13:21
Last Updated2026-09-22T17:13:21

LINK COPIED TO CLIPBOARD