PatchSiren

Omarchy CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Omarchy CVE published 2026-10-11

CVE-2026-108913

CVE-2026-108913 is a high-severity vulnerability in Omarchy 4 before 4.0.1 that allows code execution via a third-party theme. The vulnerability exists because files placed into ~/.local/state/omarchy/current/theme may include executable content from an untrusted Git repository. This emphasizes the need for defenders to verify and update installations, restrict third-party theme installation, and monitor [truncated]