Junglewise Threat Intelligence

CVE-2026-57233: Notepad++ path traversal in WinGup plugin extraction

CVE-2026-57233 · Severity: high · CVSS 8.1 · Published 2026-08-17

Technologies: Notepad++. Vendors: Notepad++.

Executive brief

Notepad++ is a popular source code editor with automatic plugin update functionality. A flaw in the WinGup plugin installer allows attackers to craft a malicious plugin package that overwrites DLL files belonging to other installed plugins. When Notepad++ next loads the compromised plugin, attacker code executes with the privileges of the application, potentially including administrator level if Notepad++ is running elevated.

Technical details

The vulnerability is a classic path traversal (ZIP Slip) flaw in the WinGup decompress() function used for plugin extraction. The vulnerable code joins untrusted ZIP entry filenames directly to the target directory without validating that the resulting path stays within the intended plugin folder. An attacker can create a ZIP archive with entries containing path traversal sequences (e.g., ../mimeTools/mimeTools.dll) that, when extracted, write files outside the target plugin directory and overwrite DLLs in sibling plugin folders. Exploitation requires only network access and user interaction (triggering a plugin update), with no authentication needed. The fix, released in version 8.9.7, validates ZIP entry paths before extraction to prevent directory traversal. Patch commits are available in the notepad-plus-plus repository.

Affected products

  • Notepad++ Notepad++ prior to 8.9.7

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: patched: Version 8.9.7 released

References