CVE-2026-42214Disclosure(dail8859 / notepad_next)

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script without sanitization. An attacker can craft a filename whose extension contains Lua code, which executes automatically when the victim opens the file in NotepadNext. Because luaL_openlibs() is called unconditionally, the full os, io, and package libraries are available to the injected code, enabling arbitrary command execution. This issue has been patched in version 0.14.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • notepad_next

Threat summary

  • 6 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-07); latest day: 1
  • 6 total mentions across 5 days

Affected systems

Vendors
Products
notepad_next

Deep dive

Activity timeline6 mentions / 5d
01122Mentions · 2026-05-07: 2Mentions · 2026-05-08: 1Mentions · 2026-05-09: 1Mentions · 2026-05-10: 1Mentions · 2026-05-12: 1Technical Details · 2026-05-07: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 1Technical Details · 2026-05-10: 1Technical Details · 2026-05-12: 105-0705-0805-0905-1005-12
Signal classification1 categories
Disclosure
6100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-072
Disclosure2
2026-05-081
Disclosure1
2026-05-091
Disclosure1
2026-05-101
Disclosure1
2026-05-121
Disclosure1
Full discourse6 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-42214 Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's ext… https://www.cve.org/CVERecord?id=CVE-2026-42214

    Post summary

    The post announces CVE-2026-42214 for Notepad Next, noting a flaw in the detectLanguageFromExtension() function before v0.14, but provides no PoC, exploit, or patch details.

    00010238
    57.4K followersView on X
  • Vignesh_Pravin@VigneshVic23698
    Disclosure

    CVE-2026-42214: NotepadNext Lua Injection Enables RCE https://thecybrdef.com/cve-2026-42214-notepadnext-lua-injection-rce/ #Cyberdailyupdate #Cybernews #Cybersecurity

    Post summary

    A new CVE (CVE-2026-42214) affecting NotepadNext has been disclosed, describing a Lua injection flaw that allows remote code execution; no PoC, exploit tool, or patch details are provided.

    0000036
    2 followersView on X
  • cybersecuritypath@cybrsecpath
    Disclosure

    CVE-2026-42214: NotepadNext Lua Injection Enables RCE https://thecybrdef.com/cve-2026-42214-notepadnext-lua-injection-rce/ #Cyberdailyupdate #Cybernews #Cybersecurity

    Post summary

    The article announces a newly disclosed vulnerability in NotepadNext that allows Lua injection to achieve remote code execution, with no mention of existing patches, exploits, or active attacks.

    0000030
    9 followersView on X
  • selva@SelvaKtm2
    Disclosure

    CVE-2026-42214: NotepadNext Lua Injection Enables RCE https://thecybrdef.com/cve-2026-42214-notepadnext-lua-injection-rce/ #Cyberdailyupdate #Cybernews #Cybersecurity https://t.co/x86pUGqKrl

    Post summary

    The tweet announces CVE‑2026‑42214, noting it allows RCE via Lua injection in NotepadNext, but it provides no PoC, exploit code, or patch details.

    0000086
    5 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42214 Lua Code Injection in Notepad Next Prior to Version 0.14 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42214

    Post summary

    The post announces CVE‑2026‑42214 as a Lua code injection flaw affecting Notepad Next before version 0.14, without mentioning any PoC, exploit, or patch.

    0000061
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42214 Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's ext… https://www.cve.org/CVERecord?id=CVE-2026-42214 ----- Traducción: CVE-2026-42214 Not… http://infoflow.cloud`

    Post summary

    A newly published CVE‑2026‑42214 details a flaw in Notepad Next’s language detection routine prior to v0.14.

    0000037
    75 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdail8859notepad_next---

Explore more