What is CVE-2026-18157?
CVE-2026-18157 is an argument injection vulnerability in the APT backend of yggdrasil-worker-package-manager. It allows a local attacker to manipulate apt-get command options by using specially crafted package names starting with a hyphen. Updating to the latest version is recommended to mitigate the risk.
Azərbaycanca: CVE-2026-18157, yggdrasil-worker-package-manager-in APT backend-ində arqument injection zəifliyidir. Bu, lokal hücumçuya defislə başlayan xüsusi hazırlanmış paket adları vasitəsilə apt-get əmrində seçimləri manipulyasiya etməyə imkan verir. Təsirə məruz qalmamaq üçün proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-77
FAQ2
In which software component was CVE-2026-18157 discovered?
This vulnerability was discovered in the APT backend of yggdrasil-worker-package-manager.
What should be done to protect against CVE-2026-18157?
It is recommended to update the software to the latest version to avoid being affected.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.