๐Ÿ” CVE Alert

CVE-2026-54576

UNKNOWN 0.0

mport package installation has symlink TOCTOU in chown and chmod handling

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. Prior to 2.7.8, do_actual_install() in libmport/bundle_read_install_pkg.c used path-based lstat(), chown(), stat(), and chmod() operations while installing package files. A local attacker with write access to a target directory could replace a checked file with a symlink before privileged ownership or mode changes were applied, redirecting those changes to an attacker-selected path and compromising filesystem integrity or permissions. This issue is fixed in version 2.7.8.

CWE CWE-59 CWE-367
Vendor midnightbsd
Product mport
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-23g3-7fv3-3ccf github.com: https://github.com/MidnightBSD/mport/pull/150 github.com: https://github.com/MidnightBSD/mport/commit/4676ac05b1056b54a3d38d03ae8a478bf12c9abe github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8