<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Xml on RingZero Pirate</title><link>https://ringzeropirate.github.io/en/tags/xml/</link><description>Recent content in Xml on RingZero Pirate</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 29 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://ringzeropirate.github.io/en/tags/xml/index.xml" rel="self" type="application/rss+xml"/><item><title>RCE in Notepad++ via XML Configuration Files: A Taint Analysis Journey</title><link>https://ringzeropirate.github.io/en/articles/notepadpp_rce/</link><pubDate>Fri, 29 May 2026 00:00:00 +0000</pubDate><guid>https://ringzeropirate.github.io/en/articles/notepadpp_rce/</guid><description>CVE-2026-48778 | CVE-2026-48800 | CVSS 7.8 HIGH
Notepad++ v8.9.5 — Fixed in v8.9.6.1
Reading time: 10 minuti
Responsible Disclosure Note — All findings described in this article were communicated to Don Ho (maintainer of Notepad++) prior to publication. The upstream fix has been committed to the repository notepad-plus-plus/notepad-plus-plus. The complete timeline is provided at the bottom of the article.
Table of Contents Introduction Setup: Loading the Codebase Threat Model and Attack Surface Phase 1: Taint Analysis with Semgrep Phase 2: Manual Verification of Findings CVE-2026-48778: config.</description></item></channel></rss>