Vulnerability Intelligence Report
Notepad++ “Run by system” executes *.txt.cmd when user selected *.txt (target confusion → command execution)
CVE-2026-77605
Notepad++ is a free and open-source source code editor. Prior to 8.9.8, the Folder as Workspace Run by system action in Notepad++ can resolve a different sibling file than the file selected by the user. When an attacker places a command script whose name is the selected text-file path with .cmd appended, and the user invokes Run by system on the text file on Windows 10 or Windows 11, Notepad++ can execute the sibling script as the current user instead of opening the selected file. This issue is fixed in version 8.9.8.
No Active Exploit Signals
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-20 ↗CWE-20: Improper Input Validation
CWE-706 ↗CWE-706: Use of Incorrectly-Resolved Name or Reference
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| notepad-plus-plus | notepad-plus-plus | < 8.9.8 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | GitHub, Inc. · Vendor · USA |
| Reserved | 2026-08-20T20:48:20 |
| Published | 2026-09-22T17:13:21 |
| Last Updated | 2026-09-22T17:13:21 |
Community Chatter & Buzz