PT-2026-57371 · Apko · Apko
CVE-2026-54174
·
Published
2026-07-10
·
Updated
2026-09-12
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
apko (affected versions not specified)
Description
Incomplete package integrity verification allows for data section substitution. The software verified the control section hash (such as
.PKGINFO) against the signed APKINDEX but failed to verify the data section hash, which contains the actual package files being installed. This flaw allows an attacker who compromises a mirror, poisons a cache, or performs a Man-in-the-Middle (MITM) attack during a package fetch to substitute arbitrary file contents while the control hash check still passes.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apko