🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.
-
Updated
Jul 27, 2026
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links
Add a description, image, and links to the notepad-vulnerability topic page so that developers can more easily learn about it.
To associate your repository with the notepad-vulnerability topic, visit your repo's landing page and select "manage topics."