Please do not open a public issue for security bugs in:
- The QtWebEngine wallpaper sandbox (web wallpapers can load arbitrary
author HTML/JS — see
src/WebUrlInterceptor.cppandsrc/SafeWallpaperBridge.cpp). - The SceneScript JavaScript engine (
src/backend_scene/qml_helper/SceneBackend.cpp), including the per-originLocalStoragequota enforced bysrc/backend_scene/qml_helper/LocalStorageQuota.hpp. - Symlink / path-traversal in
src/FileHelper.cpp(wallpaper config CRUD, HTML patching). - Any in-process crash that could be triggered by a malicious workshop wallpaper.
Instead, please use GitHub's Private vulnerability reporting feature:
- Go to https://github.com/CaptSilver/wallpaper-engine-kde-plugin/security
- Click Report a vulnerability.
- Fill in the form. GitHub encrypts the report in transit and the contents are only visible to repository maintainers.
We commit to:
- Acknowledging receipt within 7 days.
- Reproducing or rejecting (with reasoning) within 30 days.
- Crediting reporters in the release notes for the fix, unless they prefer anonymity.
Only the latest tagged release gets security fixes. If you're on an older one, upgrade — the pre-rename catsout fork (anything before 1.2) is unmaintained and won't be patched either.