Post #3580773
2026-07-04 11:32 UTC
Wondering why they stopped replying. One would imagine they would have a strong and well defined process for security reports, but it just seems like they sad “meh”
Replies (1)
-
@OctopusNemeses@lemmy.world 2026-07-04 13:33
KDE has a history of doing that. Plasma widgets are a gaping security hole. You can poke a hole through root. I’m pretty sure you can traverse up the JS object hierarchy from a widget and modify the whole desktop in anyway you want. At least at some point this was possible. Their response was basically “works as intended” and closed the issue.