Skip to content
Tech News
← Back to articles

Omarchy is full of security holes

read original more articles
Why This Matters

Omarchy 4.0 suffers from critical security vulnerabilities that pose significant risks to users and organizations, highlighting a concerning disregard for security best practices in its development. This underscores the importance for consumers and the industry to scrutinize the security posture of operating systems before adoption, especially when marketing claims may be misleading. The situation emphasizes the need for more transparent and security-focused development in the open-source community.

Key Takeaways

Merchants of Insecurity

25 Aug, 2026

First, a PSA: Do NOT use Omarchy if you care about security of your machine even a little bit.

You can't polish a turd

Omarchy 4.0 shipped with a collection of security issues which I can only describe as regrettable (because I promised my mum I would swear less). There are bangers like video title bash injection or all notifications being able to run arbitrary bash on your machine.

All projects have security issues but not all projects have such predictable security issues. We know how to deal with untrusted inputs. We know we should not use AI-generated bash scripts for processing untrusted input, particularly with seemingly no review.

And you can't get to a reasonably secure system by starting with a pile of bash slop and hoping others will catch and fix the issues before they are exploited.

Simply put, Omarchy doesn't treat security as important. They do role-play taking security seriously but their development practices and the ease with which they speedrun decades of security issues and invent new ones tell us much more about the security of Omarchy than Security Team announcements.

Lies or marketing?

DHH loves to say he's making the year of Linux on desktop happen. How Omarchy is the distro people should use. Showing how polished the experience is. Essentially, he's good at marketing Omarchy.

... continue reading