Tech & AI News
Hacker News

Omarchy: Any User Process Can Escalate to Root

Omarchy’s default Docker configuration added the default user to the Linux docker group, granting every process in the user’s session access to the root-owned Docker socket and allowing containers to be launched as root, mount the host filesystem, and read privileged files such as /etc/shadow. This privilege escalation affected all versions prior to 4.0.1, including 3.8.4, and was fixed by removing the docker group membership from the default configuration in the August 2026 update.