cve-2026-20841
Here are 4 public repositories matching this topic...
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links
-
Updated
Feb 12, 2026
🛠 Demonstrate remote code execution in Windows Notepad versions below 11.2510 using the CVE-2026-20841 proof of concept.
-
Updated
Mar 26, 2026
🛠 Demonstrate remote code execution in Windows Notepad via markdown links exploiting unsecured URL protocols.
-
Updated
Mar 26, 2026
Improve this page
Add a description, image, and links to the cve-2026-20841 topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the cve-2026-20841 topic, visit your repo's landing page and select "manage topics."