CVE-2026-54585EPSS p43.7%
CVE-2026-54585CVE-2026-54585
Description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
Scoring
| EPSS | 0.54% probability of exploitation · percentile 43.7% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-17 |