Successful exploitation of the string injection vulnerability could allow an attacker to obtain memory address information or crash the application.
https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-044/
https://llgsjsm.github.io/cve-2026-3008/
https://github.com/notepad-plus-plus/notepad-plus-plus/issues/17960
https://github.com/llgsjsm/cve-2026-3008
https://community.notepad-plus-plus.org/topic/27500/notepad-v8-9-4-release-candidate
Published: 2026-04-27
Updated: 2026-04-27
Base Score: 6.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:P
Severity: Medium
Base Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Severity: Critical
Base Score: 10
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Severity: Critical