At today's meeting, Omarchy & Open Source funding was discussed. Security was one aspect of that. And, on cue, Brodie Robertson has a video out about: This Security Bug Is Too Funny To Ignore It has to do with Kitty terminal (now the default terminal in Omarchy) with kind of crazy default settings. Like "allow_remote=yes". Some links:
As a POC, unzip the attached pwn.zip <https://github.com/kovidgoyal/kitty/files/3749391/pwn.zip> file, and run |cat pwn.txt| in a kitty instance with remote control enabled. It will run the command |touch /tmp/pwned|. This could easily have been called README instead and the command could have been |rm -rf /|. The kitty got pwned by a cat! This breaks a lot of deep implicit assumptions, such as "catting a file should be like, the safest thing to do, ever". Ouch!
https://github.com/kovidgoyal/kitty/issues/2084 It has been known for several decades that terminal control sequences are a security nightmare. They can get injected to the terminal by the most innocuous actions, such as cat-ting a text file or ... github.com Kitty's remote control is fundamentally insecure · Issue #2084 · kovidgoyal/kitty <#> It has been known for several decades that terminal control sequences are a security nightmare. They can get injected to the terminal by the most innocuous actions, such as cat-ting a text file or receiving an e-mail or IM message (if yo... 🔗 https://github.com/kovidgoyal/kitty/issues/2084 <https://github.com/kovidgoyal/kitty/issues/2084> x.com blasty (@bl4sty) on X <#> 🚨 RELEASE: Omarchy Linux Kitty terminal Remote Code Execution exploit 🚨 Stop. Using. This. GARBAGE. If you install kitty (a popular terminal emulator) on Omarchy Linux you open yourself to REMOTE CODE EXECUTION BY LOOKING AT THINGS. in the screenshot you can see `curl something` leading to si… 🔗 https://x.com/bl4sty/status/2096647017992982592 <https://x.com/bl4sty/status/2096647017992982592>
On Wed, Sep 9, 2026 at 12:21 AM Ron via Talk <talk@lists.gtalug.org> wrote:
At today's meeting, Omarchy & Open Source funding was discussed. Security was one aspect of that.
Having played with Hyprland sufficiently to present it at a previous GTALUG meeting, I consider its approach -- and indeed that of Omarchy that insists upon it -- to be little more than a large niche. Despite some of the nice innovations brought on by the "return to the terminal" movement -- such as Nerd Fonts, yazi, and ghostty -- I just don't see the mainstream reverting to CLI. Too much of the Internet is graphically oriented, and cut/paste without a pointing device remains painful after all these years. In addition, the concept of a distribution that reverts from a long Linux tradition of adapting-to-the-user's-preferences to Omarchy's one-size-fits-all approach is also one that I don't think will have lasting appeal. Indeed, Omarchy doesn't even claim to be a distribution but rather a very specific set of choices, configurations and included applications to a core Arch system (which to me describes a distinct distribution, they're being disingenuous here). And yet, as Ron has pointed out, those choices can adversely affect novice installers who may not know that Omarchy's choices have greatly prioritized look-and-feel over even basic security design. Who know what else lurks? What intrigued me the most about this, and the reason I brought it up, is that I am absolutely gobsmacked that out of all the distributions and FOSS projects, it's *THIS ONE *that has attracted more than* $13M *in funding and the support of a number of industry heavyweights. Not CachyOS, which is IMO a far better approach to Arch that still allows one to use the Hyprland DM. Not Bazzite or SteamOS, the choices of gamers who want the opposite of CLI. And certainly not Debian, the ultimate upstream distro without which Ubuntu and Mint wouldn't even exist. I don't get it. I just hope the foundation spends its money wisely, and promotes a diversity of FOSS projects beyond its founder's plaything. - Evan
And, on cue, Brodie Robertson has a video out about: This Security Bug Is Too Funny To Ignore
It has to do with Kitty terminal (now the default terminal in Omarchy) with kind of crazy default settings. Like "allow_remote=yes".
Some links:
As a POC, unzip the attached pwn.zip <https://github.com/kovidgoyal/kitty/files/3749391/pwn.zip> file, and run cat pwn.txt in a kitty instance with remote control enabled. It will run the command touch /tmp/pwned. This could easily have been called README instead and the command could have been rm -rf /. The kitty got pwned by a cat! This breaks a lot of deep implicit assumptions, such as "catting a file should be like, the safest thing to do, ever".
Ouch!
https://github.com/kovidgoyal/kitty/issues/2084 [image: It has been known for several decades that terminal control sequences are a security nightmare. They can get injected to the terminal by the most innocuous actions, such as cat-ting a text file or ...]
github.com
Kitty's remote control is fundamentally insecure · Issue #2084 · kovidgoyal/kitty <#m_3792626484105069800_>
It has been known for several decades that terminal control sequences are a security nightmare. They can get injected to the terminal by the most innocuous actions, such as cat-ting a text file or receiving an e-mail or IM message (if yo...
🔗 https://github.com/kovidgoyal/kitty/issues/2084 <https://github.com/kovidgoyal/kitty/issues/2084>
x.com
blasty (@bl4sty) on X <#m_3792626484105069800_>
🚨 RELEASE: Omarchy Linux Kitty terminal Remote Code Execution exploit 🚨 Stop. Using. This. GARBAGE. If you install kitty (a popular terminal emulator) on Omarchy Linux you open yourself to REMOTE CODE EXECUTION BY LOOKING AT THINGS. in the screenshot you can see `curl something` leading to si…
🔗 https://x.com/bl4sty/status/2096647017992982592 <https://x.com/bl4sty/status/2096647017992982592>
------------------------------------ Description: GTALUG Talk Unsubscribe via Talk-unsubscribe@lists.gtalug.org Start a new thread: talk@lists.gtalug.org This message archived at https://lists.gtalug.org/archives/list/talk@lists.gtalug.org/message/4UHFZJF...
-- Evan Leibovitch, Toronto Canada @evanleibovitch / @el56
participants (2)
-
Evan Leibovitch -
Ron