Notepad++ release 8.9.8
-
Notepad++ release 8.9.8 is available:
https://notepad-plus-plus.org/news/v898-released/
Notepad++ v8.9.8 vulnerability fix, bug-fixes & new features:
- Vulnerabilty: Fix an eventual crash while loading UDL. CVE ID not assigned yet
- Vulnerabilty: Fix an eventual crash when loading a UTF-16 file. CVE ID not assigned yet
- Vulnerabilty: Fix out-of-bounds array write. CVE ID not assigned yet
- Vulnerabilty: Fix authenticode verification bypass. CVE ID not assigned yet
- Vulnerabilty: Fix a TOCTOU issue in the Notepad++ Updater (WinGUp). CVE ID not assigned yet
- Vulnerabilty: Fix session backup path-traversal allowing deletiion outside backup directory. CVE ID not assigned yet
- Vulnerabilty: Fix potential exposure of Windows login info (SMB/NTLM) via UNC path. CVE ID not assigned yet 1, CVE ID not assigned yet 2, CVE ID not assigned yet 3, CVE ID not assigned yet 4
- Vulnerabilty: Fix shortcuts.xml HMAC bypass via the “Run a Macro Multiple Times”. CVE ID not assigned yet
- Vulnerabilty: Fix Null pointer in NPPM_SAVESESSION handler causing crash. CVE ID not assigned yet
- Vulnerabilty: Fix stack buffer overflow caused by overlong session paths. CVE ID not assigned yet
- Vulnerabilty: Fix Folder as Workspace “Run by system” target hijacking issue. CVE ID not assigned yet
- Vulnerabilty: Fix install-path injection possibility with PowerShell. CVE ID not assigned yet
- Vulnerabilty: Fix lower IL (Integrity Level) process sends WM_COMMAND to higher IL Notepad++. CVE ID not assigned yet
- Vulnerabilty: Fix Notepad++ UIPI Bypass via WM_COPYDATA. CVE ID not assigned yet
- Fix crash in WM_COPYDATA COPYDATA_PARAMS for invalid payload. (Fix #18207)
- Fix crash in API NPPM_ALLOCATE* calls. (Fix #18222)
- Add an option to allow loading symlinks in Folder as Workspace. (Fix #18226)
- Regression: Fix loading session for alone subview and doc/tab with untitle name. (Fix #18294)
- Fix CJK IME issues in Save As dialog. (Fix #11582, #15431, #16772, #12225, #12366)
- Update to Scintilla 5.6.6 & Lexilla 5.5.3. (Implement #18290)
- Add plugin deactivation capability. (Fix #18206)
- Add “-monitoringMode” command line argument to open files with monitoring enabled. (Fix #18188)
- Fix Proxy Settings issue in portable mode. (Fix #13382)
- Fix langs.xml model update not not applying file extension fields. (Fix #18220)
- Fix luminosity slider in ChooseColor not visible in dark mode. (Fix #12451)
- Fix empty sub-menus in compact language menu. (Fix #18202)
- Fix Search Results vertical scrolling not matching with OS mouse settings. (Implement #18194)
- Use modern question mark icon in dark message box. (Fix Repported in comment)
- Format count numbers using current locale separators when needed. (Fix #18190)
Auto-updater will be triggered in about 1 week, if no critical issue found in this release.
-
A serious regression: #18314
For that one, I have a simple fix ready and users already confirmed that it works ok.There is also unconfirmed #18315, for which the user also stated that reverting to the previous v8.9.7 helps. But IDK what to think about that one, I cannot reproduce and from its description I don’t really get what could be going on there, can you take a look at it?
-
@donho I began seeing this message pop up

Why is it suddenly concerned about my network path? And why would it expose my login information, and to who if im in a trusted network from a trusted PC?
-
@Danny-Duplechian From my cursory reading of the change logs, there is a lot of new security-related functionality, specifically related to NTLM authentication.
I’m NOT an expert, but npp is now checking with you before accessing non-local paths, in an attempt to determine what should (not) be trusted.
These non-local paths may appear in your .npp-session file, among others.
If these reads are done on untrusted servers, your “NTLMv2 hash” may (will?) be sent and possibly used against you.
If you recognize the server, click Load or Always load. -
After updating to 8.9.8, the “Plugins Admin” selection has disappeared under the “Plugins” menu.

-
When you ran the installer, did you turn off the following checkmark?

You need to have Plugins Admin enabled (checkmarked) in the installer to have it in the Plugins menu when you run. If you run the installer again, you can turn it on when you get to that step in the installation.
(Also, if you shared your ?-menu’s Debug Info, we could have seen whether it said
WinGUp: presentor not – because without WinGUp, the Plugins Admin won’t work. That would’ve been removed by uncheckmarking both Plugins Admin and Auto-Updater in the list of checkboxes from the screenshot.) -
Sorry for not providing complete info.
I did have the Pugins Admin checked during installation (I usually install a new version with the same options as the previous version).
Here is the debug info:
Notepad++ v8.9.8 (64-bit)
Build time: Aug 23 2026 - 17:22:44
Scintilla/Lexilla included: 5.6.6/5.5.3
Boost Regex included: 1_90
pugixml included: 1.16
nlohmann JSON included: 3.12.0
Path: C:\Program Files\Notepad++\notepad++.exe
Command Line: “C:\Program Files\Notepad++\change.log”
Admin mode: ON
Local Conf mode: OFF
Cloud Config: OFF
WinGUp: present
disableNppAutoUpdate.xml: absent
Periodic Backup: OFF
Placeholders: OFF
Scintilla Rendering Mode: SC_TECHNOLOGY_DEFAULT (0)
Multi-instance Mode: monoInst
asNotepad: OFF
File Status Auto-Detection: cdEnabledNew (for current file/tab only)
Dark Mode: OFF
Display Info:
primary monitor: 1920x1200, scaling 100%
visible monitors count: 1
installed Display Class adapters:
0000: Description - NVIDIA GeForce GT 1030
0000: DriverVersion - 27.21.14.6140
OS Name: Windows 7 Ultimate (64-bit)
OS Build: 7601.24544
Current ANSI codepage: 1250
Plugins:
ComparePlugin (2.0.2)
ElasticTabstops (1.5)
HexEditor (0.9.14)
mimeTools (3.1)
NppConverter (4.7)
NppExport (0.4) -
Everything there looks good so far, so nothing there. That makes me think it’s the Mark of the Web.
Exit Notepad++.
Open up Windows Explorer, navigate to
C:\Program Files\Notepad++. Right click onnotepad++.exe, do Properties, and make sure the bottom of the General tab doesn’t have the “unblock” checkbox:
if it does, checkmark it, and choose Apply / OK
Then go to
c:\Program Files\Notepad++\Plugins\Config, and do the same right-click Properties > General check onnppPluginList.dll. (Since Notepad++ runs, but the Plugins Admin doesn’t show up, this is most likely. I just started with the exe to be methodical.)Then also check
c:\Program Files\Notepad++\updater\gup.exe, just to make sure it will update properly in the future.If that works: then, in the future, if you manually ran the installer exe , you might want to check for the “unblock” on the installer before you do – I think if you unblock that, it will then not block the exe/dll that it installs. Similarly when downloading the zipfiles, unblock the zipfile, and everything you extract will inherit being unblocked.
-
Thanks for the tips.
None of the .exe files had the blocks.
I ran the update manually and how finally the Plugins Admin option has shown up.
I was wondering whether there was some change in nppPluginList.dll that might have been incompatible with my OS (Windows 7). But it seems everything is OK for now.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login