A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-88"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/18xxx/CVE-2026-18157.json"
}{
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "0.1.4"
},
{
"introduced": "0.2.0"
},
{
"fixed": "0.2.4"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}