minus-squareClassy Hatter@sopuli.xyztoOpen Source@lemmy.ml•LibreOffice learns to speak Markdown in version 26.2linkfedilinkarrow-up33·20 days agoI don’t know the technicalities, but Markdown supports links, and it’s possible to craft a link that downloads a file and then executes it. You can look up the Notepad.exe RCE vulnerability from this year. linkfedilink
minus-squareClassy Hatter@sopuli.xyztoOpen Source@lemmy.ml•LibreOffice learns to speak Markdown in version 26.2linkfedilinkarrow-up57·20 days agoHopefully it doesn’t have any Remote Code Execution vulnerabilities, like Microslop’s implementation had. linkfedilink
I don’t know the technicalities, but Markdown supports links, and it’s possible to craft a link that downloads a file and then executes it. You can look up the Notepad.exe RCE vulnerability from this year.