Fetching from the wire…
Public story · 2026-08-31 · high
A docker-group membership baked into setup let any app on the desktop mount the host filesystem into a root container, no password asked.
Why now: The disclosure went up August 30, and Omarchy's fix is already in 4.0.1.
Omarchy's installer added the default user to the docker group, putting every desktop app one command away from root, per 0xcc's disclosure post. Any process running in the desktop session could ask the root-owned Docker daemon to mount arbitrary host paths into a new container running as root. No password, no sudo prompt, no dialog telling the user it happened.
The bug affected the 3.x ISO through build 3.8.4 and every release before 4.0.1. It sat in the installer across multiple versions. Omarchy fixed it in 4.0.1 after the disclosure.
Docker-group membership has been root-equivalent for as long as Docker has had a group at all. Anyone in that group can bind-mount the host root into a container. From there, they can read or write anywhere the Docker daemon can reach, no exploit chain needed. That part isn't new. What's new is a distro granting the membership automatically at install, with nothing telling the user it happened.
Each link below shares sources, entities, or timing with this story.
MCP uses Docker / Shared entity: Docker / Shared topic / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover Docker; overlapping topics (container, docker).
E2B partners with Docker / Shared entity: Docker / Earlier coverage / Tension
Linked by a graph relationship (E2B partners with Docker); both cover Docker; earlier Docker coverage from 2026-08-18.
MCP uses Docker / Shared entity: Docker / Shared topic / Earlier coverage / Tension
Linked by a graph relationship (MCP uses Docker); both cover Docker; overlapping topics (container, daemon, docker).
MCP uses Docker / Shared entity: Docker / Earlier coverage
Linked by a graph relationship (MCP uses Docker); both cover Docker; earlier Docker coverage from 2026-08-21.
Docker supports Claude Code / Shared entity: Docker / Earlier coverage
Linked by a graph relationship (Docker supports Claude Code); both cover Docker; earlier Docker coverage from 2026-03-28.
Linked by a graph relationship (Docker supports Claude Code); both cover Docker; earlier Docker coverage from 2026-03-03.
E2B partners with Docker / Shared entity: Docker / Shared topic / Earlier coverage
Linked by a graph relationship (E2B partners with Docker); both cover Docker; overlapping topics (container, could, docker).
Docker supports Claude Code / Shared entity: Docker / Shared topic / Earlier coverage
Linked by a graph relationship (Docker supports Claude Code); both cover Docker; overlapping topics (container, docker).