this post was submitted on 11 Feb 2026
126 points (98.5% liked)

Technology

82329 readers
4371 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] _edge@discuss.tchncs.de 4 points 3 weeks ago

Is there a non-sense free description.

So far, i learned that notepad can open links from Markdown. I assume Markdown calls some Windows API open(link) where link is any string. That's hardly a vulnerability by itself, that's working as designed.

Where does the code execution happen? Is it open(https://hackersite.com/exploite.exe)? Can't be. They're not that stupid.

Is it open(file:///PowerShell.exe?atbitaryCodeHere)? Who would allow this?

Or open(teams://magic/doThing)?

This sounds like trying to blame notepad (and by proxy all app developers) for a design flaw in the ecosystem