CVE-2026-39958
oma-topic: name Field in Topic Manifests (topic.json) May Allow CRLF Injection
CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
13th
oma is a package manager for AOSC OS. Prior to 1.25.2, oma-topics is responsible for fetching metadata for testing repositories (topics) named "Topic Manifests" ({mirror}/debs/manifest/topics.json) from remote repository servers, registering them as APT source entries. However, the name field in said metadata were not checked for transliteration. In this case, a malicious party may supply a malformed Topic Manifest, which may cause malicious APT source entries to be added to /etc/apt/sources.list.d/atm.list as oma-topics finishes fetching and registering metadata. This vulnerability is fixed in 1.25.2.
| CWE | CWE-93 |
| Vendor | aosc-dev |
| Product | oma |
| Published | Apr 9, 2026 |
| Last Updated | Apr 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for aosc-dev oma
Be the first to know when new critical vulnerabilities affecting aosc-dev oma are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
AOSC-Dev / oma
< 1.25.1