Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
Published: 2026-09-17
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Filesystem integrity compromise
Action: Patch
AI Analysis

Impact

mport is the MidnightBSD package manager. Prior to version 2.7.8, the create_sample_file() function in libmport/bundle_read_install_pkg.c failed to constrain absolute source and destination paths from the sample-file manifest directive to the configured installation root. A malicious or malformed package manifest can therefore direct privileged sample-file handling to copy or write files outside the installation root, potentially overwriting critical system files and undermining filesystem integrity. The weakness is a path traversal flaw, identified as CWE‑22.

Affected Systems

All MidnightBSD installations running mport 2.7.7 or earlier are vulnerable. The issue resides in the mport package manager component, affecting any package that includes sample-file manifest entries. Users must be aware that any package installed by an account with installation privileges on those versions is at risk.

Risk and Exploitability

The CVSS score of 6.0 indicates moderate severity, while the EPSS score of less than 1% suggests a very low current probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits are known. Nevertheless, an adversary who can install or modify a package manifest—requiring privileged access to run mport—could overwrite arbitrary files outside the root directory, potentially facilitating privilege escalation or system compromise. The overall risk remains moderate, but the impact of successful exploitation would be significant.

Generated by OpenCVE AI on September 19, 2026 at 02:48 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to mport version 2.7.8 or later to apply the path-constraining fix
  • Avoid installing or accepting packages that contain sample-file directives from untrusted sources
  • Verify the integrity of package manifests before installation, and ensure that only trusted packages are installed

Generated by OpenCVE AI on September 19, 2026 at 02:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Midnightbsd
Midnightbsd mport
Vendors & Products Midnightbsd
Midnightbsd mport

Thu, 17 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
Title mport sample file handling can write outside the configured root
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Midnightbsd Mport
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T17:21:25.082Z

Reserved: 2026-06-15T19:15:27.344Z

Link: CVE-2026-54585

cve-icon Vulnrichment

Updated: 2026-09-17T17:21:12.343Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T17:16:43.747

Modified: 2026-09-17T21:15:06.427

Link: CVE-2026-54585

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T03:00:13Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')