PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links
exploit notepad cve windows-notepad command-injection 2026 cve-2026-20841 notepad-vulnerability notepad-exoploit securewithumer
-
Updated
Feb 12, 2026