{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2025-15556",
  "revision": 1,
  "title": "Notepad++ — updater installs without an integrity check",
  "summary": "Notepad++ before 8.8.9 accepts update metadata and installers from its updater without confirming they are genuine, so anyone able to redirect the update traffic gets their own installer run with the user's privileges.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.5,
    "vector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.01747,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "high",
    "kev_added": "2026-02-12",
    "prerequisites": "A position from which the attacker can intercept or redirect the updater's traffic."
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "Notepad++ 8.8.9"
    ]
  },
  "kill_chain": "initial_access",
  "recommended_action": "Update Notepad++ to 8.8.9 or later now; on machines that updated over networks you do not control, treat the host as suspect until checked.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-15556",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2025-15556",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2025-15556",
      "retrieved_at": "2026-09-24T08:51:39.744Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-15556",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/notepad-plus-plus/notepad-plus-plus/commit/bcf2aa68ef414338d717e20e059459570ed6c5ab"
    },
    {
      "type": "vendor_advisory",
      "url": "https://github.com/notepad-plus-plus/wingup/commit/ce0037549995ed0396cc363544d14b3425614fdb"
    },
    {
      "type": "vendor_advisory",
      "url": "https://notepad-plus-plus.org/news/hijacked-incident-info-update/"
    }
  ],
  "published_at": "2026-02-03T01:15:57.757Z",
  "issued_at": "2026-09-24T08:51:39.744Z",
  "tags": [
    "notepad-plus-plus",
    "supply-chain",
    "update-integrity",
    "kev"
  ]
}
