{"id":"CVE-2025-52939","summary":"Potential heap-buffer overflow vulnerability in NotepadNext","details":"Out-of-bounds Write vulnerability in dail8859 NotepadNext (src/lua/src modules). This vulnerability is associated with program files ldebug.C, lvm.C.\n\nThis issue affects NotepadNext: through v0.11.","modified":"2026-08-12T14:52:44.271085Z","published":"2025-06-23T09:26:56.917Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52939.json","cna_assigner":"GovTech CSG","cwe_ids":["CWE-787"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/52xxx/CVE-2025-52939.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-52939"},{"type":"FIX","url":"https://github.com/dail8859/NotepadNext/commit/3e928d91b8fc8bb5c77801ee8652f41e98d12571"},{"type":"FIX","url":"https://github.com/dail8859/NotepadNext/pull/757/files"},{"type":"PACKAGE","url":"https://github.com/dail8859/NotepadNext"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/dail8859/notepadnext","events":[{"introduced":"0"},{"fixed":"5875f739855ea0c80dba7a1f10ec8ab248587697"},{"fixed":"3e928d91b8fc8bb5c77801ee8652f41e98d12571"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"v0.11"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v0.11","v0.10","v0.9","v0.8","v0.7","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.6","v0.5.6","v0.5.5","v0.5.4","v0.5.3","v0.5.2","v0.5.1","v0.5","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4","v0.3.3","v0.3.2","v0.3.1","v0.3","v0.2","v0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-52939.json","vanir_signatures_modified":"2026-08-12T14:52:44Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/dail8859/notepadnext/commit/3e928d91b8fc8bb5c77801ee8652f41e98d12571","target":{"file":"src/lua/src/lvm.c"},"deprecated":false,"digest":{"line_hashes":["109160025163517894246555464311927905168","159618918195428700036162165579477364744","283141188429944630371482485266135235772","221963446402022317367091809335463570364","244764617910085233208160284415443226461","237849260543562680110344945870625485769","37562800747512701822999390229154263700","219524848240838254345629611037116750206","108725855737991599988774000492808822080"],"threshold":0.9},"id":"CVE-2025-52939-195fee2c","signature_type":"Line"},{"id":"CVE-2025-52939-2334d450","signature_type":"Function","signature_version":"v1","source":"https://github.com/dail8859/notepadnext/commit/3e928d91b8fc8bb5c77801ee8652f41e98d12571","target":{"file":"src/lua/src/ldebug.c","function":"luaG_runerror"},"deprecated":false,"digest":{"function_hash":"258277994694759977460106283175756763753","length":337}},{"deprecated":false,"digest":{"function_hash":"64633869205412628438747901374518934461","length":1059},"id":"CVE-2025-52939-3b006176","signature_type":"Function","signature_version":"v1","source":"https://github.com/dail8859/notepadnext/commit/3e928d91b8fc8bb5c77801ee8652f41e98d12571","target":{"file":"src/lua/src/lvm.c","function":"luaV_concat"}},{"digest":{"line_hashes":["47064890593937786897531178058191810844","138912143874367540401104822690246485002","288992524067399130896317049326973779263","197042422895227100265124330746984136449","302716735206890089776290500244915829848"],"threshold":0.9},"id":"CVE-2025-52939-d89fc0d5","signature_type":"Line","signature_version":"v1","source":"https://github.com/dail8859/notepadnext/commit/3e928d91b8fc8bb5c77801ee8652f41e98d12571","target":{"file":"src/lua/src/ldebug.c"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:N/AU:Y/R:U/V:C/RE:M/U:Red"}]}