Argument Injection Vulnerability in Yggdrasil Worker Package Manager by Red Hat
CVE-2026-18157

7.8HIGH

What is CVE-2026-18157?

A flaw exists in the Yggdrasil Worker Package Manager that allows a local attacker with access to exploit an argument injection vulnerability within the APT backend. This issue occurs when specially crafted package names, starting with a hyphen, are misinterpreted as command options by apt-get. If exploited, the attacker may enhance their access to achieve remote code execution with root privileges, thereby compromising the integrity, confidentiality, and availability of the system.

Affected Version(s)

yggdrasil-worker-package-manager 0 < 0.1.4

yggdrasil-worker-package-manager 0.2.0 < 0.2.4

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank AISLE Research for reporting this issue.
.