PT-2026-95009 · Mport · Mport

CVE-2026-54575

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description Privileged package fetch and cache-cleaning operations use race-prone path handling within libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle read install pkg.c, libmport/delete primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path can exploit this to redirect package downloads, cleanup, or install-related side effects outside the intended cache. Additionally, the affected lifecycle helper paths utilize shell-form invocation, which increases the risk of command-line interpretation during privileged helper execution.
Recommendations Update to version 2.7.8.

Exploit

Fix

OS Command Injection

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54575
GHSA-H387-G4PF-28CJ

Affected Products

Mport