Zerush ( Zerush@lemmy.ml ) to Open Source@lemmy.ml · 7 months agoLibreOffice learns to speak Markdown in version 26.2www.theregister.comexternal-linkmessage-square10linkfedilinkarrow-up1194
arrow-up1194external-linkLibreOffice learns to speak Markdown in version 26.2www.theregister.comZerush ( Zerush@lemmy.ml ) to Open Source@lemmy.ml · 7 months agomessage-square10linkfedilink
minus-squareClassy Hatter ( ClassyHatter@sopuli.xyz ) linkfedilinkarrow-up37·7 months agoHopefully it doesn’t have any Remote Code Execution vulnerabilities, like Microslop’s implementation had.
minus-squarejdnewmil ( jdnewmil@lemmy.ca ) linkfedilinkarrow-up13·7 months agoHow in the world did they manage that? Did they implement it internally as a TCP API and expose it?
minus-squareClassy Hatter ( ClassyHatter@sopuli.xyz ) linkfedilinkarrow-up25·7 months agoI don’t know the technicalities, but Markdown supports links, and it’s possible to craft a link that downloads a file and then executes it. You can look up the Notepad.exe RCE vulnerability from this year.
minus-squareBig Baby Thor ( thorhop@sopuli.xyz ) linkfedilinkarrow-up16·7 months agoBasically Notepad would pass the link to ShellEx and could launch executables.
minus-squarejol ( jol@discuss.tchncs.de ) linkfedilinkarrow-up3·7 months agoThey probably vibe coded it, and only copilot reviewed and merged the code.
Hopefully it doesn’t have any Remote Code Execution vulnerabilities, like Microslop’s implementation had.
How in the world did they manage that? Did they implement it internally as a TCP API and expose it?
I don’t know the technicalities, but Markdown supports links, and it’s possible to craft a link that downloads a file and then executes it. You can look up the Notepad.exe RCE vulnerability from this year.
Basically Notepad would pass the link to ShellEx and could launch executables.
They probably vibe coded it, and only copilot reviewed and merged the code.