A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
Omarchy is just a bunch of dotfiles in a Hugo Boss trenchcoat pretending to be a linux distribution.
I don’t get how this project just received 8 million dollars. It really is just a preconfigured arch linux.
It was all just a bunch of rich tech bros that made that $8M investment, with $1M from DHH himself.
Its not the standard investment from another company where they do some due diligence. This was just a “we think this is the future of Linux” vibe investment.