this post was submitted on 09 Mar 2026
234 points (99.6% liked)

Open Source

46163 readers
87 users here now

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

founded 6 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[โ€“] ClassyHatter@sopuli.xyz 18 points 1 month ago (1 children)

I don't know the technicalities, but Markdown supports links, and it's possible to craft a link that downloads a file and then executes it. You can look up the Notepad.exe RCE vulnerability from this year.

[โ€“] thorhop@sopuli.xyz 12 points 1 month ago

Basically Notepad would pass the link to ShellEx and could launch executables.