CVE-2026-48800 is a high-severity vulnerability in Notepad++ that allows for command injection. The vulnerability exists in the way Notepad++ handles user-defined commands in the shortcuts.xml file. An attacker can exploit this vulnerability by injecting malicious commands, which can then be executed when the user clicks on the corresponding entry in the Run menu. This vulnerability has been fixed in Note [truncated]
Notepad++ versions 8.9.4 through 8.9.6 contain a local privilege escalation vulnerability. The installer invokes powershell.exe without using an absolute path after setting the working directory to the installation contextMenu directory. If an attacker can pre-place a malicious powershell.exe in a user-writable custom installation directory, and a privileged user later runs the installer and selects that [truncated]