A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
Man I love this thread, I was starting to think I was the unreasonable one for thinking Omarchy is a hyped PoS dotfile skin. To learn it goes deeper into a fascists plaything is wild to me, I got some good intuition I guess.