PT-2026-95015 · Midnightbsd · Mport

CVE-2026-54585

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

6.0

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager contains an issue where the create sample file() function in libmport/bundle read install pkg.c fails to constrain absolute source and destination paths from the sample-file manifest directive to mport->root. This allows a malicious or malformed package manifest to direct privileged sample-file handling to copy or write files outside the configured installation root, which can compromise local filesystem integrity.
Recommendations Update to version 2.7.8.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54585
GHSA-XQJC-RXMM-P27V

Affected Products

Mport