PT-2026-31657 · Oma+2 · Oma+2

CVE-2026-39958

·

Published

2026-04-09

·

Updated

2026-04-09

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions oma versions prior to 1.25.2
Description oma, a package manager for AOSC OS, has an issue where the oma-topics component improperly handles metadata from remote repository servers. Specifically, it fetches metadata for testing repositories named "Topic Manifests" from endpoints like {mirror}/debs/manifest/topics.json and registers them as APT source entries. A lack of input validation on the 'name' field within this metadata allows a malicious party to inject malformed Topic Manifests, potentially leading to the addition of malicious APT source entries to /etc/apt/sources.list.d/atm.list.
Recommendations Update to version 1.25.2 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39958
GHSA-86JC-7R6Q-CR3F

Affected Products

Aosc Os
Apt
Oma