https://seclists.org/oss-sec/2026/q3/556: BusyBox dpkg applet: OS command injection
Published Aug 24, 2026
·Updated
Affected Software
1 affected component
Busybox Busybox>=1.36.1<=1.37.0
No privilege boundary is crossed. Commands run with the privileges of the user invoking the BusyBox dpkg applet; this is typically root when dpkg is run by an administrator.
The issue was confirmed on BusyBox 1.36.1 and 1.37.0.git HEAD. The report states that it is present through current BusyBox.