Vulnerability in MidnightBSD Package Manager Allows Metadata Extraction Manipulation
CVE-2026-54584
5.3MEDIUM
What is CVE-2026-54584?
The MidnightBSD Package Manager (mport) prior to version 2.7.8 contains a vulnerability that arises from improper handling of the TMPDIR environment variable during package metafile extraction. In scenarios where mport operates with elevated privileges, an attacker with control over the environment variables can redirect the temporary metadata extraction process to a location of their choice, potentially allowing for the manipulation of package files. This issue has been addressed in version 2.7.8, which implements safeguards by rejecting unsafe TMPDIR values in privileged contexts and disallowing empty TMPDIR settings.
Affected Version(s)
mport < 2.7.8
