High severity8.1NVD Advisory· Published Aug 17, 2026· Updated Aug 18, 2026
CVE-2026-57233
CVE-2026-57233
Description
Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version 8.9.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <8.9.7
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.