Package management vulnerability in MidnightBSD
CVE-2026-54577
2LOW
What is CVE-2026-54577?
In versions prior to 2.7.8 of the MidnightBSD Package Manager, a flaw existed in the audit command implementation. When specifying options like '-r' before a package, the original arguments passed led to an unintentional auditing of the option instead of the targeted package. This misconfiguration resulted in the inability to properly identify vulnerable packages, creating a risk for users relying on the tool for package management. With the update in version 2.7.8, the parsing process has been corrected, ensuring that the command properly resets the option index before using the adjusted arguments, thus enhancing the reliability of the auditing process.
Affected Version(s)
mport < 2.7.8
