PT-2026-96107 · Midnightbsd · Mport

CVE-2026-54584

·

Published

2026-09-21

·

Updated

2026-09-25

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mport versions prior to 2.7.8
Description The MidnightBSD Package Manager improperly handles the TMPDIR environment variable when extracting package metafiles, even when operating as root or within setuid/setgid contexts. An attacker who can control the environment during a privileged invocation may redirect the temporary metadata extraction to a location under their control.
Recommendations Update to version 2.7.8.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54584
GHSA-4VV3-3H8R-Q6MQ

Affected Products

Mport