A security issue in Omarchy’s default Docker configuration meant that
essentially every program running in the user’s desktop session could escalate
to root without a password, sudo, or a privilege prompt.
If you use Omarchy, the most important takeaway is
simple: update to 4.0.1.
I reported this issue privately through the project’s responsible-disclosure
process. The underlying configuration has since been patched, so I’m publishing
the details now to explain what the issue is and let users know to update their
systems.
why do you have to shit on hyprland? you could have the most boring aesthetic experience on earth but as far as i know this is an omarchy issue, hyprland doesn’t have any vulnerabilities, and it’s not just an aesthetic thing, you can do a lot of shit beyond simply aesthetic on hyprland. security and good looks are not mutually exclusive. and i dont think hyprland is here like “the thing” that will attract users. i don’t see new linux users using hyprland except in this case because it comes preconfigured, otherwise it’s for power users.
I am shitting on Hyprland because DHH, who is responsible for the mess that is Omarchy, is in bed with Vaxry and they both enable each other. I did not say that Hyprland has any vulnerabilities. I said that people who have a hard on for aesthetics do so because they are compensating for a lack of substance most often. I was specifically referring to this privilidge escalation fuck up.
Well, the attempt is made for it to be part of just that. See Omarchy.
Almost all programs that implement some sort of GUI the way XFCE or dwm does are for power users, it’s called being on Linux. The exception here is maybe the latest GNOME release. Hyprland is also for the r/UNIXPORN crowd.