Executive brief
Notepad++ is a popular free source code editor used by software developers. Versions prior to 8.9.7 contain a vulnerability in the Windows installer that could allow an attacker to execute arbitrary commands with elevated privileges if they control the installation directory path. An attacker could exploit this by crafting a malicious installation path that contains PowerShell code, which would be executed when a user installs the software and selects the context menu component.
Technical details
This is a PowerShell command injection vulnerability in the Notepad++ Windows installer (nppSetup.nsi). The vulnerability occurs in the RegisterMSIX function, which passes the attacker-controlled installation directory ($INSTDIR) directly into a PowerShell -Command string without proper escaping. An attacker can inject PowerShell subexpression syntax such as $() to execute arbitrary commands. The attack requires local access and user interaction (selecting the context menu component during installation). The vulnerability affects Windows 11 x64 and ARM64 installers prior to version 8.9.7, where it was fixed by passing INSTDIR as an environment variable instead of inline in the command string.
Affected products
- Notepad++ Notepad++ prior to 8.9.7
Timeline
- 2026-08-11: disclosed
- 2024-07-14: patched: Fixed in version 8.9.7