Impact
The mport audit command mistakenly examined an option token rather than the intended package, causing a false-negative result that could allow a vulnerable package to remain unnoticed; this flaw is rooted in improper argument parsing and stale option state (CWE-20) and insufficient security checks (CWE-693).
Affected Systems
MidnightBSD’s mport package manager before version 2.7.8 is affected, including any installation or automation that passes options such as -r before a package name to the audit command.
Risk and Exploitability
With a CVSS score of 2 and an EPSS score below 1%, and not listed in CISA KEV, the likelihood of exploitation is low; however, an attacker who can influence audit executions could bypass visibility of vulnerabilities, making prompt patching advisable. The vulnerability requires local or scripted command execution, so it is primarily a local or privileged scenario rather than an internet-facing exploit. Insurance against undetected vulnerabilities is best achieved by applying the 2.7.8 fix or later.
OpenCVE Enrichment