Path Traversal Vulnerability in MidnightBSD Package Manager
CVE-2026-54585

6MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 September 2026

What is CVE-2026-54585?

The MidnightBSD Package Manager is vulnerable to a path traversal issue in the create_sample_file() function, found in libmport/bundle_read_install_pkg.c. This vulnerability allows a malicious package manifest to bypass path constraints, potentially leading to the copying or writing of files outside the designated installation root. This can undermine local filesystem integrity, posing significant security risks. The issue has been addressed in version 2.7.8, which is recommended for all users to ensure secure operation.

Affected Version(s)

mport < 2.7.8

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.