๐Ÿ” CVE Alert

CVE-2026-54583

UNKNOWN 0.0

mport package bundle downloads allow unsafe destination filenames

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.

CWE CWE-22 CWE-73
Vendor midnightbsd
Product mport
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-mr62-mqwj-vhh3 github.com: https://github.com/MidnightBSD/mport/pull/125 github.com: https://github.com/MidnightBSD/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8 github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8