Vulnerability in MidnightBSD Package Manager Allows Metadata Extraction Manipulation
CVE-2026-54584

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-54584?

The MidnightBSD Package Manager (mport) prior to version 2.7.8 contains a vulnerability that arises from improper handling of the TMPDIR environment variable during package metafile extraction. In scenarios where mport operates with elevated privileges, an attacker with control over the environment variables can redirect the temporary metadata extraction process to a location of their choice, potentially allowing for the manipulation of package files. This issue has been addressed in version 2.7.8, which implements safeguards by rejecting unsafe TMPDIR values in privileged contexts and disallowing empty TMPDIR settings.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.