Junglewise Threat Intelligence

CVE-2026-52886: Notepad++ path traversal via session.xml backupFilePath

CVE-2026-52886 · Severity: info · Published 2026-08-17

Technologies: Notepad++. Vendors: Notepad++.

Executive brief

Notepad++ is a free source code editor used by programmers to write and edit code. Prior to version 8.9.7, the application failed to properly validate file paths when restoring backed-up sessions, allowing an attacker to craft a malicious session file that reads arbitrary files from a user's computer and displays them in the editor. An attacker could exploit this to access sensitive files like passwords, configuration files, or other user data.

Technical details

A path traversal vulnerability exists in Notepad++'s session restoration logic. The application validates the backupFilePath attribute from session.xml using std::wstring::starts_with() to ensure paths stay within the backup directory, but fails to normalize file paths before validation. This allows an attacker to bypass the check using parent-directory sequences (e.g., "../") during snapshot-mode restoration. An attacker with the ability to modify or supply a malicious session.xml file can cause Notepad++ to load and display arbitrary user-readable files outside the intended backup directory. The vulnerability requires local file system access or the ability to modify the session.xml configuration file. This issue was fixed in version 8.9.7 by implementing proper path normalization during session file loading.

Affected products

  • Notepad++ Notepad++ prior to 8.9.7

Timeline

  • 2026-08-17: disclosed
  • 2026-07-14: patched: v8.9.7 released with path normalization fix

References