CVE-2026-5525 Details
Description
A stack-based buffer overflow vulnerability exists in Notepad++ version 8.9.3 in the file drop handler component. When a user drags and drops a directory path of exactly 259 characters without a trailing backslash, the application appends a backslash and null terminator without proper bounds checking, resulting in a stack buffer overflow and application crash (STATUS_STACK_BUFFER_OVERRUN).
A stack-based buffer overflow vulnerability has been identified in Notepad++ version 8.9.3. The issue arises in the file drop handler component when a user drags and drops a directory path that is exactly 259 characters long, without a trailing backslash. The application improperly appends a backslash and null terminator, leading to a stack buffer overflow and causing the application to crash with a 'STATUS_STACK_BUFFER_OVERRUN' error.
Users can update to the latest version of Notepad++ where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17921 | CISA-ADP | ExploitIssue TrackingMitigationVendor Advisory |
| https://github.com/notepad-plus-plus/notepad-plus-plus/commit/bfe7514d68bc559534c046c4ef2d1865267aa2b0 | securin | Patch |
| https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17921 | securin | ExploitIssue TrackingMitigationVendor Advisory |
| https://github.com/notepad-plus-plus/notepad-plus-plus/pull/17930 | securin | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-121 | Stack-based Buffer Overflow | securin |
Affected Products
| Product | Versions |
|---|---|
| notepad-plus-plus notepad++ | 8.9.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | securin |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | Initial Analysis | [email protected] |
| Apr 10, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | New CVE Received | securin |