๐Ÿ” CVE Alert

CVE-2026-54585

UNKNOWN 0.0

mport sample file handling can write outside the configured root

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.

CWE CWE-22
Vendor midnightbsd
Product mport
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for midnightbsd mport

Be the first to know when new unknown vulnerabilities affecting midnightbsd mport are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

MidnightBSD / mport
< 2.7.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/MidnightBSD/mport/security/advisories/GHSA-xqjc-rxmm-p27v github.com: https://github.com/MidnightBSD/mport/pull/122 github.com: https://github.com/MidnightBSD/mport/commit/36a42c8ddbd23ee9eb72c4c17596eb92cb423cf0 github.com: https://github.com/MidnightBSD/mport/releases/tag/2.7.8