logoalt Hacker News

seritoolstoday at 8:46 AM0 repliesview on HN

You are mistaken:

> The malicious code would execute in the security context of the user who opened the Markdown file, giving the attacker the same permissions as that user.