CVE-2026-3008

MEDIUM

Vulnerability in Notepad++

Title source: cna
STIX 2.1

Description

Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.

Exploits (1)

nomisec WRITEUP
by llgsjsm · poc
https://github.com/llgsjsm/cve-2026-3008

Scores

CVSS v3 6.6
EPSS 0.0001
EPSS Percentile 1.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-134
Status published
Products (1)
Notepad++/Notepad++ 8.9.3
Published Apr 27, 2026
Tracked Since Apr 27, 2026