Path Handling Vulnerability in MidnightBSD Package Manager
CVE-2026-54575
5.8MEDIUM
What is CVE-2026-54575?
The MidnightBSD Package Manager contains a vulnerability due to race-prone path handling in multiple files related to privileged operations. A local attacker with write access to a participating package cache could exploit this flaw to interfere with package downloads and cleaning operations. The risk is exacerbated by shell-form invocation during privileged executions, allowing for potential command-line interpretation issues. This vulnerability has been addressed in version 2.7.8 of the package manager.
Affected Version(s)
mport < 2.7.8
