Omarchy: Any User Process Can Escalate to Root
Summary
The article reports a critical security flaw in Omarchy's default Docker configuration that grants root access to ordinary user processes via the Docker socket, enabling privilege escalation. It recommends updating to version 4.0.1, explains the root cause (docker group membership), and suggests Podman as a safer alternative. It also highlights broader lessons about secure defaults and developer machine security.