PT-2026-95004 · Midnightbsd · Mport

CVE-2026-54583

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager fails to consistently reject bundle filenames that are empty or contain dots, dot-dot sequences, or slashes within the libmport/fetch.c file. This occurs because the is valid bundle filename() check is missing when composing package download and write paths. Consequently, malicious package index data can use an unsafe value in the indexEntry->bundlefile variable to write downloaded package data outside the intended cache location or to an unsafe destination name.
Recommendations Update to version 2.7.8.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54583
GHSA-MR62-MQWJ-VHH3

Affected Products

Mport