PT-2026-31657 · Apt+2 · Apt+2

Published

2026-04-09

·

Updated

2026-04-09

·

CVE-2026-39958

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions oma versions prior to 1.25.2
Description oma, a package manager for AOSC OS, has an issue where the oma-topics component improperly handles metadata from remote repository servers. Specifically, it fetches metadata for testing repositories named "Topic Manifests" from endpoints like {mirror}/debs/manifest/topics.json and registers them as APT source entries. A lack of input validation on the 'name' field within this metadata allows a malicious party to inject malformed Topic Manifests, potentially leading to the addition of malicious APT source entries to /etc/apt/sources.list.d/atm.list.
Recommendations Update to version 1.25.2 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-39958

Affected Products

Aosc Os
Apt
Oma