Description
A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Fri, 31 Jul 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: Remote Code Execution via APT Argument Injection | Yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: remote code execution via apt argument injection |
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/o:redhat:enterprise_linux:10 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
|
| References |
|
Fri, 31 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful exploitation could lead to remote code execution (RCE) with root privileges, enabling the attacker to fully compromise the system's integrity, confidentiality, and availability. | |
| Title | yggdrasil-worker-package-manager: yggdrasil-worker-package-manager: Remote Code Execution via APT Argument Injection | |
| Weaknesses | CWE-88 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-07-31T02:38:28.243Z
Reserved: 2026-07-28T20:03:33.510Z
Link: CVE-2026-18157
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses