PT-2026-95009 · Mport · Mport
CVE-2026-54575
·
Published
2026-09-17
·
Updated
2026-09-17
CVSS v4.0
5.8
Medium
| Vector | AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mport versions prior to 2.7.8
Description
Privileged package fetch and cache-cleaning operations use race-prone path handling within
libmport/fetch.c, libmport/clean.c, libmport/util.c, libmport/bundle read install pkg.c, libmport/delete primative.c, and libexec/mport.create/mport.create.c. A local attacker with write access to a participating package cache or staging path can exploit this to redirect package downloads, cleanup, or install-related side effects outside the intended cache. Additionally, the affected lifecycle helper paths utilize shell-form invocation, which increases the risk of command-line interpretation during privileged helper execution.Recommendations
Update to version 2.7.8.
Exploit
Fix
OS Command Injection
Time Of Check To Time Of Use
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mport