Researchers disclosed multiple severe flaws in Pling-based Linux software marketplaces and the Electron-based PlingStore client that could enable account takeover, malicious software distribution, and remote code execution. A stored, wormable XSS issue in Pling-powered web stores could let attackers hijack user sessions, alter listings, and upload trojanized packages, creating a potential software supply-chain compromise that propagates across marketplace content.
The native PlingStore application was also found vulnerable to drive-by RCE because its local ocs-manager WebSocket service accepted commands from any website without origin validation or authentication while the app was running, undermining the browser same-origin policy protections normally relied on to isolate web content. The researcher said Pling/OpenDesktop did not respond to repeated disclosure attempts before public release, while related issues in KDE Discover (CVE-2021-28117) and GNOME Shell Extensions were reportedly fixed more quickly.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2021-06-22, Positive Security publicly disclosed severe unpatched vulnerabilities in Pling-based Linux software marketplaces and the native PlingStore application after repeated attempts to reach Pling/OpenDesktop failed. The disclosed issues included a stored wormable XSS that could enable account hijacking and supply-chain attacks, and a drive-by RCE path via the Electron app's local WebSocket service.
The article reports that GNOME Shell Extensions had an XSS issue and that GNOME remediated it within 24 hours of disclosure.
The Positive Security article states that KDE Discover had a separate URI-handling code execution vulnerability, tracked as CVE-2021-28117, and that KDE fixed it quickly after disclosure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.