๐Ÿ” CVE Alert

CVE-2026-54584

UNKNOWN 0.0

mport trusts environment-controlled temporary directories in privileged metadata extraction

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.

CWE CWE-73 CWE-377
Vendor midnightbsd
Product mport
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-4vv3-3h8r-q6mq github.com: https://github.com/MidnightBSD/mport/pull/123 github.com: https://github.com/MidnightBSD/mport/commit/3790fa49a36cb085f48b204ef189fb82bbee621a github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8