CVE-2025-56383

High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Notepad++ v8.8.3 has a DLL hijacking vulnerability, which can replace the original DLL file to execute malicious code. NOTE: this is disputed by multiple parties because the behavior only occurs when a user installs the product into a directory tree that allows write access by arbitrary unprivileged users.

Published 2025-09-26. Last modified 2026-06-17.