๐Ÿ” CVE Alert

CVE-2026-108913

HIGH 7.1
CVSS Score
7.1
EPSS Score
0.0%
EPSS Percentile
0th

omarchy-theme-set in Omarchy 4 before 4.0.1 allows code execution via a third-party theme because the files placed into ~/.local/state/omarchy/current/theme may include executable content from an untrusted Git repository.

CWE CWE-829
Vendor omarchy
Product omarchy
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for omarchy omarchy

Be the first to know when new high vulnerabilities affecting omarchy omarchy are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
Low

Affected Versions

Omarchy / Omarchy
4.0.0 < 4.0.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/omacom/omarchy/security/advisories/GHSA-mxm5-5433-ggf5 github.com: https://github.com/omacom/omarchy/pull/7884 github.com: https://github.com/omacom/omarchy/commit/ef6d9e6605b121df15bf310e630e04f0c1119fc8 github.com: https://github.com/omacom/omarchy/releases/tag/v4.0.1