Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 04 Mar 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Getsol
Getsol eopkg |
|
| CPEs | cpe:2.3:a:getsol:eopkg:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Getsol
Getsol eopkg |
|
| Metrics |
cvssV3_1
|
Fri, 02 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 01 Jan 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | eopkg is a Solus package manager implemented in python3. In versions prior to 4.4.0, a malicious package could escape the directory set by `--destdir`. This requires the installation of a package from a malicious or compromised source. Files in such packages would not be installed in the path given by `--destdir`, but on a different location on the host. The issue has been fixed in v4.4.0. Users only installing packages from the Solus repositories are not affected. | |
| Title | eopkg has Path Traversal: '../filedir' vulnerability | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-02T18:52:58.220Z
Reserved: 2025-12-29T03:00:29.275Z
Link: CVE-2026-21436
Updated: 2026-01-02T18:52:46.207Z
Status : Analyzed
Published: 2026-01-01T18:15:41.203
Modified: 2026-03-04T21:33:14.970
Link: CVE-2026-21436
No data.
OpenCVE Enrichment
Updated: 2026-04-18T08:45:41Z