What is CVE-2026-57233?
CVE-2026-57233 is a path traversal vulnerability in the WinGup decompress function of Notepad++ versions prior to 8.9.7. It allows a malicious ZIP file with entries like '../mimeTools/mimeTools.dll' to overwrite a DLL in a sibling plugin directory. Users should update Notepad++ to the latest version.
Azərbaycanca: CVE-2026-57233 zəifliyi Notepad++ proqramının 8.9.7 versiyasından əvvəlki versiyalarında WinGup dekompressiya funksiyasında yol keçidi (path traversal) qüsurudur. Bu, zərərli ZIP faylı vasitəsilə qonşu plugin qovluğunda DLL faylının üzərinə yazmağa imkan verir. İstifadəçilər Notepad++ proqramını ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Which versions of Notepad++ are affected by CVE-2026-57233?
This vulnerability affects versions of Notepad++ prior to 8.9.7.
How can a malicious ZIP file exploit CVE-2026-57233?
A malicious ZIP file can include entries like '../mimeTools/mimeTools.dll' to overwrite a DLL in a sibling plugin directory through a path traversal flaw in the WinGup decompress function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.