๐Ÿ” CVE Alert

CVE-2026-54575

UNKNOWN 0.0

mport package fetch and clean paths are vulnerable to TOCTOU filesystem races

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. Prior to 2.7.8, privileged package fetch and cache-cleaning operations used race-prone path handling across libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle_read_install_pkg.c, libmport/delete_primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path could race path checks and replacement operations to redirect package downloads, cleanup, or install-related side effects outside the intended cache. The affected lifecycle helper paths also used shell-form invocation, increasing command-line interpretation risk during privileged helper execution. This issue is fixed in version 2.7.8.

CWE CWE-78 CWE-367
Vendor midnightbsd
Product mport
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-h387-g4pf-28cj github.com: https://github.com/MidnightBSD/mport/pull/118 github.com: https://github.com/MidnightBSD/mport/commit/29154b0fdfb5806568ed1277e88d942bad6d1169 github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8