CVE-2026-18157

HIGH

Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection

Title source: cna
STIX 2.1

Description

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.

Scores

CVSS v3 7.8
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-88
Status published
Products (3)
Red Hat/Red Hat Enterprise Linux 10
RedHatInsights/yggdrasil-worker-package-manager < 0.1.4
RedHatInsights/yggdrasil-worker-package-manager 0.2.0 - 0.2.4
Published Jul 31, 2026
Tracked Since Jul 31, 2026