Notepad++ 8.9.8 Offers Security Fixes and Crash Patches
The free and open-source text/code editor that's a staple on millions of Windows PCs, has shipped version 8.9.8.
Notepad++, the free and open-source text/code editor that's a staple on millions of Windows PCs, has shipped version 8.9.8. The update landed doesn't bring flashy new features, it closes off a notable batch of security holes and a couple of crash bugs, worth installing sooner rather than later if you use Notepad++ daily.
What's New in 8.9.8
Security fixes:
- Fixed a TOCTOU (time-of-check to time-of-use) issue in the Notepad++ Updater (WinGUp)
- Fixed a session backup path-traversal bug that could allow file deletion outside the backup directory
- Fixed potential exposure of Windows login credentials (SMB/NTLM) via UNC paths
- Fixed a shortcuts.xml HMAC bypass reachable through "Run a Macro Multiple Times"
- Fixed a "Folder as Workspace" target-hijacking issue tied to how the app determines what's "run by system"
- Fixed an install-path injection risk involving PowerShell
- Fixed an issue where a lower Integrity Level (IL) process could send WM_COMMAND messages to a higher-IL Notepad++ instance
Stability fixes:
- Fixed a null pointer bug in the NPPM_SAVESESSION handler that was causing crashes
- Fixed a stack buffer overflow triggered by overlong session paths
Why It Matters
Several of these fixes close privilege-escalation and credential-leak vectors rather than being routine bug tidying, so this is a recommended update for anyone running Notepad++ in a shared or networked environment.
Download
Grab the update directly from the official site: notepad-plus-plus.org/downloads/v8.9.8
Full release notes: notepad-plus-plus.org/news/v898-released
Track version history and update checks via UpdateStar: notepad.updatestar.com