A newly disclosed vulnerability, CVE-2025-49144, affects the Notepad++ installer and could allow attackers to gain full control of a system. The flaw enables malicious actors to place a harmful file in the same directory as the installer, typically the ‘Downloads’ folder, which can be leveraged during installation to compromise the machine. This issue is addressed in Notepad++ version 8.8.2, and users are strongly advised to update to the latest fix to stay protected.