Omahub
← All plugins
M

CyberGhost VPN

by Miguel

CyberGhost WireGuard connections through NetworkManager, with country switching in the Omarchy bar.

Security review

Potentially dangerous behavior detected · 20 findings

Deterministic scan — not a security guarantee

High
Risk level
High
Analyzed commit
43c3476
Scanned
5 days ago
  • high destructive_filesystem tests/test_validation.py:52

    Destructive operation on the root filesystem or a block device.

    rm -rf /",
  • high destructive_filesystem tests/test_validation.py:117

    Destructive operation on the root filesystem or a block device.

    rm -rf /",
  • medium external_hosts Service.qml:311

    Downloads or connects to an external HTTP(S) host.

    curl", "--ipv4", "--silent", "--show-error", "--fail-with-body", "--connect-timeout", "2", "--max-time", "4", "--max-filesize", "32768", "--proto", "=https", "https://ipwho.is/?type=ipv4"]
  • medium external_hosts Service.qml:640

    Downloads or connects to an external HTTP(S) host.

    curl", "--ipv4", "--silent", "--show-error", "--fail-with-body", "--connect-timeout", "2", "--max-time", "4", "--max-filesize", "32768", "--proto", "=https", "https://ipwho.is/?type=ipv4"]
  • medium package_manager …/workflows/ci.yml:36

    System package manager operation.

    apt-get update
  • medium package_manager …/workflows/ci.yml:37

    System package manager operation.

    apt-get install -y shellcheck qt6-declarative-dev-tools qml6-module-qttest qml6-module-qtqml-workerscript qml6-module-qtquick-window qml6-module-qtquick-controls qml6-module-qtquick-templates
  • medium package_manager …/workflows/ci.yml:35

    System-wide Python package installation (not --user).

    pip install ruff==0.16.9 pytest requests
  • medium sudo Service.qml:458

    Command runs with sudo, elevating the process beyond the plugin environment.

    sudo wg-quick down cyberghost"
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo in tests."""
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get update
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo apt-get install -y shellcheck qt6-declarative-dev-tools qml6-module-qttest qml6-module-qtqml-workerscript qml6-module-qtquick-window qml6-module-qtquick-controls qml6-module-qtquick-templates
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S python-requests')."
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo authentication remain with the vendor and sudo, on a real terminal. No
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo and CyberGhost passwords in this terminal only.")
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo policy unchanged. Only recognize the
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo pacman -S jq)." >&2
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo prompts and output are never hidden from the user.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo in a unit test. All production QML files are inspected so extracting a component does not evade that guard.
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo bypassed the Arch compatibility wrapper. With explicit owner approval, a narrowly scoped root-owned `/usr/local/bin/openvpn` launcher was installed without modifying sudoers, packaged OpenVPN or 
  • Command runs with sudo, elevating the process beyond the plugin environment.

    sudo mktemp -d …)` captured sudo's fingerprint-reader auth prompt into the variable, corrupting the staging directory path. Replaced with a PID-based predictable path (`/tmp/cyberghost-install-root-$$

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
43c3476
Reviewed
4 days ago

The plugin is a legitimate CyberGhost VPN client that manages WireGuard connections through NetworkManager. The deterministic scan's high-risk flags are largely false positives: the `rm -rf /` appears in a unit test that verifies the runner rejects destructive commands, and the sudo/package-manager findings are in developer scripts, CI, or documentation rather than the runtime plugin. The actual runtime code (QML widget + Python runner) runs unprivileged and only interacts with NetworkManager, CyberGhost's API, and a public IP lookup service.

  • The runner contains a hardcoded CyberGhost API key (the vendor's public key), which is expected but worth noting.
  • The plugin stores CyberGhost credentials in plaintext at ~/.cyberghost/native.ini; standard for such tools but users should be aware.
  • Install/cleanup scripts invoke sudo and pacman, but only after explicit user confirmation in a visible terminal.
  • The plugin queries ipwho.is for public IP on a default 8-second interval; this is a privacy consideration, not a security risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/27mfp/miguel.cyberghost --enable
Widgets #bar #security

CyberGhost VPN for Omarchy

<p align="center"><img src="icon.svg" alt="CyberGhost VPN" width="128" height="128"></p>

A WireGuard VPN plugin for the Omarchy bar. Choose a country and connect with one click. The tunnel is an ordinary NetworkManager connection, so on Omarchy it needs no root helper, no extra system packages and no password prompt.

Open the CyberGhost plugin in the Omarchy plugin directory

Preview

<p align="center"> <img src="docs/screenshots/screenshot-disconnected.png" alt="CyberGhost VPN disconnected with connection details hidden" width="360"> <img src="docs/screenshots/screenshot_connected.png" alt="CyberGhost VPN connected to Portugal with WireGuard active" width="360"> </p>

Install

omarchy plugin add https://github.com/27mfp/miguel.cyberghost.git --enable

Open the ghost icon and complete the setup steps:

  1. If python-requests is missing, install it from the panel (it opens Omarchy's floating terminal).
  2. Link your CyberGhost account. Native credentials are stored in ~/.cyberghost/native.ini.

That's it: connecting uses NetworkManager, which Omarchy already runs, and its Polkit policy already lets your desktop session manage network connections. You can also run bash install.sh from a checkout for guided setup. The vendor CLI is not required.

Use

  • Select a country under Location.
  • While connected, the tunnel also appears as CyberGhost VPN in nmcli and Omarchy's network tools. It lives only in memory and is gone after a NetworkManager restart or reboot.
  • Selecting a country alone never reconnects.
  • Use the switch in the panel header to connect or disconnect. If you pick a different country while connected, Switch to … moves the tunnel in one click; choosing a country alone never reconnects.
  • Panel shortcuts: t or Enter toggles the VPN, c copies the public IP (or click the IP), h hides details, r refreshes, Esc closes.
  • Account → Log out forgets this device's login (~/.cyberghost/native.ini) after a second confirming click, disconnecting first if needed. An account from the CyberGhost CLI's own config.ini is shown but left alone. Logging out does not remove the device from your CyberGhost account; do that on CyberGhost's website if you no longer use it.
  • Left-click opens the panel; middle- and right-click toggle the VPN.

Server selection is automatic, in this order: the vendor CLI's inventory if installed; CyberGhost's own live server list (least loaded first) while your login session is valid (about a day after Link account); otherwise real server names from your local cache, probed for the fastest reachable host. While the session is valid, the plugin fills that cache for every country in the background, from your own account. The Account section shows "syncing servers" with its progress. Nothing needs to be set up or refreshed by hand. Linking your account again refreshes the list.

python3 ~/.config/omarchy/plugins/miguel.cyberghost/cyberghost_runner.py probe --all

Scope and limits

  • Supported mode: native WireGuard traffic connections only.
  • OpenVPN, streaming, torrent, and manual-server controls are not supported.
  • This is not a kill switch and does not claim leak protection or anonymity.
  • VPN DNS is set exclusively on the tunnel (~. routing domain). If you chose a provider with omarchy dns, Omarchy's global DNS still applies and those queries travel through the tunnel.
  • A separate vendor VPN session is not managed by this plugin.
  • Public-IP lookup uses ipwho.is; privacy mode only masks the displayed values.

The plugin preserves the vendor's ~/.cyberghost/config.ini. Disconnect before removing or upgrading from an experimental vendor-based version.

Update and remove

omarchy plugin update miguel.cyberghost

Updates need no extra step. Upgrading from 1.6.x or earlier: disconnect once (the old helper removes its own tunnel), then use Settings → Advanced → Remove old root helper…, or run bash scripts/remove-legacy-helper.sh. Disconnect before removal. See the installer reference for details.

Development

pytest -q
ruff check .
ruff format --check .
bash scripts/test-qml.sh

Read the release checklist, architecture, and testing guide for additional details. The repository contains experimental vendor compatibility code, but it is not part of the supported release.