CVE-2026-21437
eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could include files that are not tracked by `eopkg`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be shown by `lseopkg` and related tools. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected.
Vendor
Product
CWE
Yayın Tarihi
2026-01-01 18:15:41
Güncelleme
2026-03-04 21:31:50
Source Identifier
security-advisories@github.com
KEV Date Added
-