CVE-2026-4546

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The attack is restricted to local execution. The attack requires a high level of complexity. The exploitability is said to be difficult. The vendor was contacted early about this disclosure but did not respond in any way.
References
Link Resource
https://drive.google.com/file/d/1w5-ztNIN28mPuidtjlsilKsKKQQNOiIJ/view Permissions Required
https://vuldb.com/?ctiid.352373 Permissions Required
https://vuldb.com/?id.352373 Third Party Advisory VDB Entry
https://vuldb.com/?submit.774778 Exploit Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

cpe:2.3:a:flos-freeware:notepad2:4.2.25:*:*:*:*:*:*:*

History

30 Apr 2026, 14:25

Type Values Removed Values Added
References () https://drive.google.com/file/d/1w5-ztNIN28mPuidtjlsilKsKKQQNOiIJ/view - () https://drive.google.com/file/d/1w5-ztNIN28mPuidtjlsilKsKKQQNOiIJ/view - Permissions Required
References () https://vuldb.com/?ctiid.352373 - () https://vuldb.com/?ctiid.352373 - Permissions Required
References () https://vuldb.com/?id.352373 - () https://vuldb.com/?id.352373 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.774778 - () https://vuldb.com/?submit.774778 - Exploit, Third Party Advisory, VDB Entry
Summary
  • (es) Se ha identificado una debilidad en Flos Freeware Notepad2 4.2.25. Esto afecta a una función desconocida en la biblioteca TextShaping.dll. La ejecución de una manipulación puede conducir a una ruta de búsqueda incontrolada. El ataque está restringido a la ejecución local. El ataque requiere un alto nivel de complejidad. Se dice que la explotabilidad es difícil. El proveedor fue contactado tempranamente sobre esta divulgación pero no respondió de ninguna manera.
CPE cpe:2.3:a:flos-freeware:notepad2:4.2.25:*:*:*:*:*:*:*
First Time Flos-freeware notepad2
Flos-freeware

22 Mar 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-22 14:16

Updated : 2026-04-30 14:25


NVD link : CVE-2026-4546

Mitre link : CVE-2026-4546

CVE.ORG link : CVE-2026-4546


JSON object : View

Products Affected

flos-freeware

  • notepad2
CWE
CWE-426

Untrusted Search Path

CWE-427

Uncontrolled Search Path Element