Argument Injection Vulnerability in Yggdrasil Worker Package Manager by Red Hat
CVE-2026-18157
7.8HIGH
What is CVE-2026-18157?
A flaw exists in the Yggdrasil Worker Package Manager that allows a local attacker with access to exploit an argument injection vulnerability within the APT backend. This issue occurs when specially crafted package names, starting with a hyphen, are misinterpreted as command options by apt-get. If exploited, the attacker may enhance their access to achieve remote code execution with root privileges, thereby compromising the integrity, confidentiality, and availability of the system.
Affected Version(s)
yggdrasil-worker-package-manager 0 < 0.1.4
yggdrasil-worker-package-manager 0.2.0 < 0.2.4
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank AISLE Research for reporting this issue.
