Remix.run Logo
graemep 6 hours ago

Is this a big deal? is it also not a problem with anything that renders clickable links? Browsers, email clients, whatever.

Is this not a problem with anything that offers a preview of markdown (or HTML, or anything with embedded links)?

laserbeam 4 hours ago | parent [-]

The problem is notepad itself would download and execute bad stuff if you click the evil link. If you would paste that same link in a browser you'd be ok.

And the problem is a notepad app is expected to be dead simple, have few features, and be hard to get wrong while implementing.

graemep 4 hours ago | parent [-]

So Notepad will download and execute itself rather than launch an appropriate application to handle the URL? That was not clear to me.