Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo without canonical containment validation, allowing an entry such as ../mimeTools/mimeTools.dll to overwrite a DLL in a sibling plugin directory and execute attacker-controlled code when Notepad++ next loads that plugin. This issue is fixed in version 8.9.7.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-22"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57233.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "8.9.7"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-57233.json"
[
{
"target": {
"function": "decompress",
"file": "src/winmain.cpp"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/wingup/commit/7670296a5c7fdec624e0a45dbde51059a7d735a8",
"id": "CVE-2026-57233-21266b00",
"signature_version": "v1",
"digest": {
"length": 2237.0,
"function_hash": "169323833541709493284522899890746305713"
},
"signature_type": "Function"
},
{
"target": {
"function": "AboutDlg::run_dlgProc",
"file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/6634650414ff91220a4c353b7fe5ad741af0f9f9",
"id": "CVE-2026-57233-77046d11",
"signature_version": "v1",
"digest": {
"length": 2313.0,
"function_hash": "321789678466323583525587903832696399039"
},
"signature_type": "Function"
},
{
"target": {
"file": "PowerEditor/src/WinControls/AboutDlg/AboutDlg.cpp"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/6634650414ff91220a4c353b7fe5ad741af0f9f9",
"id": "CVE-2026-57233-de8dc4ca",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"73934179812655448165055737310699482624",
"165596075505432413455088505965299296812",
"15697846664367097651332048867224774793",
"327363084166932039838311470772824169691",
"27658911648692079515982892510481891031"
]
},
"signature_type": "Line"
},
{
"target": {
"file": "src/winmain.cpp"
},
"deprecated": false,
"source": "https://github.com/notepad-plus-plus/wingup/commit/7670296a5c7fdec624e0a45dbde51059a7d735a8",
"id": "CVE-2026-57233-f0b3d82d",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"314407321131039278628073492534505858913",
"227176457769990210276831407942017984137",
"174145186401954165019932825963215577402",
"110081486140871945433109951405809467184",
"149367707345767057578135467637212135257",
"79730008289902968687543701463571814211"
]
},
"signature_type": "Line"
}
]
"2026-08-20T10:17:16Z"