Medium severityNVD Advisory· Published Sep 17, 2026· Updated Sep 17, 2026
CVE-2026-54585
CVE-2026-54585
Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
Affected products
1- Range: <2.7.8
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.