Notepad++ is a free and open-source source code editor. Prior to 8.9.6.1, a local process in the same interactive Windows session can send a malformed WMCOPYDATA message to Notepad++ using the COPYDATAFULLCMDLINE path. The handler appears to process COPYDATASTRUCT.lpData as an unbounded NUL-terminated wchart* instead of enforcing COPYDATASTRUCT.cbData. This vulnerability is fixed in 8.9.6.1.
{
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/48xxx/CVE-2026-48770.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:notepad-plus-plus:notepad\\+\\+:*:*:*:*:*:*:*:*",
"source": [
"CPE_RANGE",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.9.6.1"
}
]
}"2026-07-15T20:54:38Z"
[
{
"signature_type": "Line",
"target": {
"file": "PowerEditor/src/NppBigSwitch.cpp"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f20a0888a92ce557a339b833cd9d9d8e97dc797d",
"id": "CVE-2026-48770-1c7ce0ce",
"signature_version": "v1",
"digest": {
"line_hashes": [
"162310288181697253186583483991444783969",
"327332410780558114642479121942727616407",
"62105852796194859496922709386988617473",
"122949687845711758976411485800303281663",
"206924673815623729155830518488964809827",
"15391214335294048241802154834615707537",
"20546640480010927113401974569659549926",
"103146463125903476811449829160423934458",
"251376421513517918977894460196262442803",
"337263700473535808314888187364561030611",
"247182092006951224559333297524013352008",
"10328570580949893477841418692183641839",
"67166849642954784198965091577983071339",
"286269319992037249959445292252738928874"
],
"threshold": 0.9
}
},
{
"signature_type": "Function",
"target": {
"file": "PowerEditor/src/NppBigSwitch.cpp",
"function": "Notepad_plus::process"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/f20a0888a92ce557a339b833cd9d9d8e97dc797d",
"id": "CVE-2026-48770-d6902675",
"signature_version": "v1",
"digest": {
"function_hash": "141575852661808811178933808006746621686",
"length": 90114.0
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-48770.json"