PT-2026-1018 · Solus · Eopkg

Osmancanvural

·

Published

2026-01-01

·

Updated

2026-03-04

·

CVE-2026-21437

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions eopkg versions prior to 4.4.0
Description eopkg, a Solus package manager implemented in python3, contains a flaw where a malicious package could include files that are not tracked by eopkg. This requires installation of a package from a malicious or compromised source. Files within such packages would not be displayed by lseopkg and related tools. Users installing packages solely from the Solus repositories are not affected.
Recommendations Update to version 4.4.0 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-21437
GHSA-HJP7-QWRJ-6CC6

Affected Products

Eopkg