PT-2026-95017 · Midnightbsd · Mport

CVE-2026-54587

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v4.0

5.8

Medium

VectorAV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description In the MidnightBSD Package Manager, directory assets handled as ASSET DIR or ASSET DIR OWNER MODE in the libmport/bundle read install pkg.c file utilize path-based mport mkdirp(), ownership, and permission operations. A local attacker with the ability to modify part of the target installation tree can employ dot-dot traversal or substitute symlinks during a privileged package installation. This allows the attacker to cause directory creation or attribute changes to affect paths outside the intended package directories.
Recommendations Update to version 2.7.8.

Exploit

Fix

Link Following

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54587
GHSA-F69W-H3GH-R86P

Affected Products

Mport