CVE-2025-52938: DAIL8859 Notepadnext
Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Out-of-bounds Read vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files lparser.C. This issue affects NotepadNext: through v0.11. The singlevar() in lparser.c lacks a certain luaK_exp2anyregup call, leading to a heap-based buffer over-read that might affect a system that compiles untrusted Lua code.
Affected products
- DAIL8859 Notepadnext
Published 2025-06-23. Last modified 2026-06-17.