Sceawere
Vulnerability Detail
CVE-2026-108913UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Arbitrary Code Execution in Omarchy
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.1
- Creation Date
- 2h ago
- Vendor
- Omarchy
- Product
- Omarchy
- Attack Type
- CWE-829 Inclusion of Functionality from Untrusted Control Sphere
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
- Attack Complexity
- HIGH
Narrative and Response
Description
omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an untrusted Git repository.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.1",
"pubDate": "2026-10-11T16:16:31.713Z",
"pubdate": "2026-10-11T16:16:31.713Z",
"executiveSummary": "The omarchy-theme-set component in Omarchy versions prior to 4.0.1 is susceptible to an arbitrary code execution vulnerability stemming from insecure handling of theme configuration files.\nThis vulnerability is classified as an insecure deserialization or arbitrary code execution flaw, allowing attackers to execute malicious code within the context of the user running the Omarchy application.\nThe issue arises because the application automatically processes files within the ~/.local/state/omarchy/current/theme directory without sufficient validation or sanitization of executable content retrieved from untrusted third-party Git repositories.\nSuccessful exploitation allows an attacker to achieve code execution on the host system, potentially leading to a full compromise of the user account. This poses a significant risk to systems that utilize third-party themes from potentially malicious or compromised sources.\nThe vulnerability requires an attacker to convince a user to install or configure an untrusted theme, effectively leveraging social engineering or supply chain compromise of the theme repository to achieve execution.",
"technicalDetails": "The root cause of the vulnerability lies in the improper trust boundary management within the omarchy-theme-set functionality. The application architecture implicitly trusts the contents of the directory located at ~/.local/state/omarchy/current/theme. When a user configures Omarchy to utilize a third-party theme, the application pulls content from an external Git repository into this local directory.\nThe vulnerability is triggered because the application fails to distinguish between static configuration data and executable content. If a third-party theme includes malicious scripts, binaries, or configuration files that are interpreted by the host system or the application's theme engine, Omarchy executes this content without validation.\nThe attack flow begins when an attacker publishes a malicious theme to a Git repository. A victim, intending to customize their Omarchy installation, points the theme set functionality toward this untrusted repository. Omarchy clones the repository into the designated directory. Upon activation or subsequent loading of the theme, the application reads the files within the theme directory. Because the application processes these files as executable or configurable inputs, it inadvertently triggers the execution of the attacker-supplied payload.\nThe vulnerable component is the theme loading mechanism within omarchy-theme-set. Affected versions include all versions of Omarchy before 4.0.1. Exploitation does not require authentication to the application itself, as the threat vector is the user-initiated installation of themes from external sources.\nPost-exploitation, the attacker gains the ability to execute arbitrary commands with the same privileges as the user process running Omarchy. This facilitates persistence, data exfiltration, and lateral movement within the environment. Because the application interacts directly with files in the user's home directory structure, the impact is confined to the user scope, though this can often lead to further privilege escalation if other local system vulnerabilities exist."
}