{
  "id": 3502908,
  "title": "Omarchy is full of security holes",
  "url": "https://urgent.news/2026/08/26/omarchy-is-full-of-security-holes",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-26T12:17:43.000Z",
  "source": {
    "name": "Hacker News",
    "slug": "hacker-news",
    "url": "https://blog.happyfellow.dev/merchants-of-insecurity/"
  },
  "original_language": "en",
  "account": "Security vulnerabilities were discovered in Omarchy version 4.0, raising concerns about the operating system's safety. Some of the issues include video title bash injection and the ability for notifications to execute arbitrary bash commands on a user's machine. The developers have acknowledged these problems, but the recurring nature of security flaws suggests a lack of care for system security.\n\nDHH, a key figure in the project, has been criticized for his marketing tactics, which focus on impressing users with polished experiences and highlighting resolved security issues in subsequent releases. However, this approach appears to mask the project's poor security practices. The marketing team seems disingenuous, emphasizing iteration on dotfiles over basic system security.\n\nCritics argue that Omarchy doesn't treat security seriously and warn that many companies may ban its use due to the high risks involved. The team's lack of transparency in explaining the actual risks to users further fuels concern. The author urges readers not to be deceived by the project's image and to be cautious when using Omarchy, as the potential security risks could lead to significant harm.",
  "summary": null,
  "key_points": [
    "Omarchy version 4.0 contains security vulnerabilities",
    "Video title bash injection and bash command execution possible",
    "Developers acknowledge issues but project shows poor security practices"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}