Omarchy: code execution from an installed third-party theme
Omarchy theme install - a theme cloned from a third-party Git repository was staged whole, so its Lua files and terminal configs ran as the user (CVE-2026-108913)
Fixed in Omarchy 4.0.1 (2026-08-25) by maintainer PR #7884, which stops a theme installed from a Git repository from staging Lua files, terminal configs or vscode.json. Track the fix at omacom/omarchy#7884.
- Product
- Omarchy (omarchy-theme-install, omarchy-theme-set) in omacom/omarchy
- Affected versions
- Omarchy 4.0.0 (2026-08-14) and main before #7884 (2026-08-23). Fixed in 4.0.1 (2026-08-25).
- Severity
- HIGH
- Status
- Patched
- Weaknesses
- CWE-829Inclusion of Functionality from Untrusted Control Sphere
- CWE-94Improper Control of Generation of Code ('Code Injection')
- GitHub advisory
- GHSA-mxm5-5433-ggf5
Private; still in triage with the maintainer - CVE
- CVE-2026-108913
- Published
- Credit
- Finder: Aaron Elijah Mars of Aeon. Tool: Aeon (https://www.aeon.fun).
What users should do now
Upgrade to 4.0.1 or later (released 2026-08-25). It includes #7884.
- Update Omarchy from the menu (
Update > Omarchy) or runomarchy-update. The update runs a migration that re-stages the current theme once, so code from a third-party theme that is already applied is dropped without waiting for the next theme change. - If you installed a theme from a Git URL on 4.0.0, look in
~/.config/omarchy/themes/<name>/at its*.luafiles, its terminal configs (alacritty.toml,kitty.conf,foot.ini,ghostty.conf) andvscode.json. That code has already run as you, so if any of it does more than set colors, treat the account as compromised. - Only install themes from authors you trust. A theme unpacked by hand from an archive, instead of installed with
omarchy theme install, looks like one you wrote yourself and is not filtered.
Summary
omarchy theme install <url> clones a theme's Git repository into ~/.config/omarchy/themes/<name>/ and applies it with omarchy-theme-set. Before 4.0.1, omarchy-theme-set copied every file of that theme into the staged theme at ~/.local/state/omarchy/current/theme/. Many of the files Omarchy reads from there are code, not colors: Hyprland requires the theme's hyprland.lua and gum_env.lua, Neovim's theme plugin file points at the staged neovim.lua, the Alacritty, Kitty, foot and Ghostty configs include the staged terminal config (which can set the program the terminal runs), and the extension field of vscode.json is passed to the editor's --install-extension. Nothing told a theme the user wrote apart from one cloned from a stranger, so installing a third-party theme was the same as running its author's code.
Affected versions
Omarchy 4.0.0 (released 2026-08-14) and main before #7884 (merged 2026-08-23), as listed on the CVE record. Fixed in 4.0.1 (2026-08-25). Omarchy's own bundled themes and themes the user writes by hand are not the risk; only a theme cloned from a Git repository someone else controls is. Earlier releases were not reviewed.
Impact
The attacker publishes a theme and the user installs it, for example from a theme list or a shared link. CVSS 3.1 score 7.1 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L). Once the theme is applied, its author's code runs as the user:
- Right away. Applying a theme reloads Hyprland (
hyprctl reload), which drops the cached theme modules and loads the stagedhyprland.luaagain, so a theme's Lua runs as soon as it is installed. - At every login. Hyprland loads the staged
hyprland.luaandgum_env.luaeach time the session starts. - When a terminal or editor starts. Alacritty, Kitty, foot and Ghostty include the staged terminal config, Neovim loads the staged
neovim.lua, and VS Code and its forks install the marketplace extension named invscode.json.
The code runs with the user's full rights: it can read files, SSH keys and browser data and change the user's configuration. The staged copies stay in place until the theme is staged again, and omarchy theme update pulls any files the author adds later. A working exploit is withheld.
Affected code
Permalinks at b71c60f, the parent of the fix commit.
- Theme install clones the URL into the themes folder and applies it: bin/omarchy-theme-install#L32-L39
- Every file of the user theme is copied into the staged theme, with no check on where it came from: bin/omarchy-theme-set#L146-L148, then swapped in as current: bin/omarchy-theme-set#L163-L165
- Applying a theme reloads Hyprland: bin/omarchy-theme-set#L190-L208 and bin/omarchy-restart-hyprctl#L5, and the reload drops the cached theme modules: default/hypr/bootstrap.lua#L4-L29
- Hyprland requires the staged theme's Lua: default/hypr/omarchy.lua#L22-L23 (
hyprland.lua) and default/hypr/envs.lua#L5 (gum_env.lua) - Terminal configs include the staged file: config/alacritty/alacritty.toml#L1, config/kitty/kitty.conf#L1, config/foot/foot.ini#L2, config/ghostty/config#L2
- Neovim's theme plugin file is a link to the staged
neovim.lua: migrations/1785002349.sh#L3-L5 - The
extensionfield ofvscode.jsongoes to the editor's--install-extension: bin/omarchy-theme-set-vscode#L104-L121
Fix
- #7884 (commit ef6d9e6, merged 2026-08-23, shipped in 4.0.1) filters a theme at staging time when it came from a Git repository, which it tells by the
.gitfolder thatomarchy theme installleaves behind. Any*.luafile, the four terminal configs (alacritty.toml,kitty.conf,foot.ini,ghostty.conf) andvscode.jsonare dropped and named on stderr, and Omarchy generates those files from its own templates instead. Symlinks in such a theme are dropped at any depth. - Colors still work: for a theme older than
colors.toml, the palette is read from itsalacritty.tomlin a scratch folder and only the resultingcolors.tomlis staged. - The filter sits in
omarchy-theme-set, the one step every theme passes through, so it also covers themes installed before the fix and files added later byomarchy theme update. A migration re-stages the current theme once on update. - As the maintainer notes in
docs/theming.md, this marks where a theme came from and is not a sandbox: a theme unpacked by hand from an archive looks like one the user wrote and is not filtered.
Detection (for defenders)
List the themes installed from Git with ls -d ~/.config/omarchy/themes/*/.git and check each one for *.lua files, terminal configs and vscode.json. Read them for anything other than colors and fonts: Lua that starts processes or writes files, a shell, program or command setting in a terminal config, or an unexpected extension in vscode.json. On 4.0.1 or later, omarchy theme set prints the files it ignored for such a theme. A working exploit is withheld.
Timeline
- Omarchy 4.0.0 released.
- Reported privately via GitHub PVR (GHSA-mxm5-5433-ggf5).
- Maintainer merges the fix, #7884.
- Omarchy 4.0.1 released with the fix, listed under Security in the release notes.
- CVE ID requested from MITRE.
- CVE-2026-108913 published by MITRE; public write-up.
Credit
Finder: Aaron Elijah Mars of Aeon. Tool: Aeon.
References
- Fix PR (merged 2026-08-23): omacom/omarchy#7884, commit ef6d9e6
- Fixed release: Omarchy 4.0.1
- GitHub advisory: GHSA-mxm5-5433-ggf5 (private; still in triage)
- CVE: CVE-2026-108913 (assigned by MITRE)
- Affected repository: omacom/omarchy