Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary File Write
Action: Immediate Patch
AI Analysis

Impact

The vulnerability stems from missing validation of bundle filenames in mport's fetch component. Malicious package index entries can specify empty, dot, dot‑dot, or slash‑containing filenames, which are then used to construct download and write paths without proper sanitization. As a result, an attacker can cause the package manager to write files outside the intended cache directory or to overwrite arbitrary files, leading to privilege escalation or system compromise.

Affected Systems

This flaw affects all MidnightBSD system installations running mport before version 2.7.8. The vulnerable code resides in libmport/fetch.c and is relevant to all package downloads handled by mport. Vendors and users should check the installed mport version and ensure it is at least 2.7.8.

Risk and Exploitability

The CVSS score is 8.3, indicating a high severity. The EPSS score is below 1%, suggesting that the probability of exploitation is low, and it does not appear in CISA's KEV catalog. The likely attack vector is a compromised or malicious package repository; an attacker who can inject entries into a repository that a user’s mport will consume can exploit the flaw. If exploited, the attacker could write files with arbitrary names outside the intended cache directory, potentially overwriting system files or placing malicious payloads, thereby enabling privilege escalation or persistence. As no public exploit is known, the threat remains theoretical but should be mitigated promptly.

Generated by OpenCVE AI on September 19, 2026 at 02:49 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to mport 2.7.8 or later to receive the fix that enforces proper filename validation.
  • Verify the integrity of package repositories by using signed indices or trusted mirrors to prevent malicious index entries.
  • Restrict permissions on the mport cache directory and the system's package directory so that only trusted users or processes can write to these locations; consider using filesystem ACLs or chroot to contain any write attempts.

Generated by OpenCVE AI on September 19, 2026 at 02:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.
Title mport package bundle downloads allow unsafe destination filenames
Weaknesses CWE-22
CWE-73
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:00:25.780Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54583

cve-icon Vulnrichment

Updated: 2026-09-17T17:00:21.482Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.593

Modified: 2026-09-17T21:15:06.427

Link: CVE-2026-54583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path