{"rewrite":{"id":"r_1433e0de6ec03fd01fa134b9","clusterId":"c_1ad9a38052136546be0c4d19","slug":"omarchy-default-docker-setup-lets-any-user-process-escalate-to-root","model":"deepseek-v4-flash","headline":"Omarchy Default Docker Setup Lets Any User Process Escalate to Root","summary":"A security vulnerability in Omarchy's default Docker configuration lets any user process escalate to root privileges without a password or sudo. The default user is a member of the docker group, which can command the root-level Docker daemon to mount the host filesystem and read files like /etc/shadow. The setting was opt-out, not opt-in. Version 4.0.1 removes the docker group from the default configuration.","whyItMatters":"The default Omarchy account sat in the docker group, which is effectively root, and the documentation misled users into thinking Docker ran rootless, so the fix was a configuration change, not a code patch.","webCardHtml":"\u003cp\u003eThe proof of concept is straightforward. On a fresh install, a normal user gets \u0026#34;Permission denied\u0026#34; reading /etc/shadow, then runs \u0026#34;docker run --rm -v /:/hostroot alpine cat /hostroot/etc/shadow\u0026#34; and the file appears. The docker group is the whole problem: Docker itself warns that group members get root-level privileges by default. Omarchy\u0026#39;s developer documentation said the group change let users \u0026#34;run Docker as the normal user and not as root,\u0026#34; which could mislead users into thinking Docker ran rootless. The fix, applied on August 24, 2026, removes the docker group from the default configuration. Users on versions before 4.0.1 should update.\u003c/p\u003e","blueskyPost":"Omarchy's default Docker setup put the default user in the docker group, which is effectively root. A plain \"docker run\" could mount the host filesystem and read /etc/shadow. The setting was opt-out, not opt-in. Fixed in 4.0.1 by removing the group from the default config.","twitterPost":"Omarchy's default config put the default user in the docker group, which is effectively root. A \"docker run\" could mount the host filesystem and read /etc/shadow. The setting was opt-out, not opt-in. Fixed in 4.0.1 by removing the group from the default config.","threadsPost":null,"newsletterBlurb":"Omarchy's default Docker configuration let any user process escalate to root: the default account was in the docker group, which can command the root-level Docker daemon. A plain \"docker run\" could mount the host filesystem and read /etc/shadow. The fix, in version 4.0.1, removes the docker group from the default configuration.","attributionJson":"[{\"source\":\"GIGAZINE\",\"url\":\"https://gigazine.net/news/20260902-omarchy-root-creds/\",\"title\":\"Omarchyで任意のユーザープロセスがルート権限に昇格可能の脆弱性、4.0.1へのアップデートで回避可能\"}]","lintFlagsJson":null,"lintHits":0,"costUsd":0,"inputTokens":5722,"outputTokens":3063,"status":"published","repairAttempts":0,"nextRepairAt":null,"factsAttemptedAt":1788356362,"createdAt":"2026-09-02T13:28:20.000Z","publishedAt":"2026-09-02T13:32:22.000Z","updatedAt":"2026-09-02T13:32:22.000Z"},"cluster":{"id":"c_1ad9a38052136546be0c4d19","canonicalTitle":"Omarchyで任意のユーザープロセスがルート権限に昇格可能の脆弱性、4.0.1へのアップデートで回避可能","representativeArticleId":"a_4cd25107f9b0866ffeabf744","sourceCount":1,"writtenSourceCount":1,"writeAttempts":0,"isSolo":true,"entitiesJson":"{\"anime_titles\":[],\"manga_titles\":[],\"work_titles\":[],\"studios\":[],\"people\":[],\"type\":\"news\",\"domain\":\"other\",\"is_roundup\":false}","contentType":"news","status":"published","firstSeenAt":"2026-09-01T21:00:00.000Z","lastSeenAt":"2026-09-01T21:00:00.000Z","updatedAt":"2026-09-02T13:32:25.000Z"},"attribution":[{"source":"GIGAZINE","url":"https://gigazine.net/news/20260902-omarchy-root-creds/","title":"Omarchyで任意のユーザープロセスがルート権限に昇格可能の脆弱性、4.0.1へのアップデートで回避可能"}],"entities":{"anime_titles":[],"manga_titles":[],"work_titles":[],"studios":[],"people":[],"type":"news","domain":"other","is_roundup":false},"keyFacts":null}
