Midnightbsd · Mport · CVE-2026-54576
**Name of the Vulnerable Software and Affected Versions**
mport versions prior to 2.7.8
**Description**
The MidnightBSD Package Manager contains a flaw where the `do actual install()` function in `libmport/bundle read install pkg.c` utilizes path-based `lstat()`, `chown()`, `stat()`, and `chmod()` operations during package installation. A local attacker with write access to a target directory can exploit this by replacing a checked file with a symbolic link before privileged ownership or mode changes are applied. This allows the attacker to redirect these changes to an arbitrary path, potentially compromising filesystem integrity or permissions.
**Recommendations**
Update to version 2.7.8.