Path Traversal Vulnerability in MidnightBSD Package Manager
CVE-2026-54585
6MEDIUM
What is CVE-2026-54585?
The MidnightBSD Package Manager is vulnerable to a path traversal issue in the create_sample_file() function, found in libmport/bundle_read_install_pkg.c. This vulnerability allows a malicious package manifest to bypass path constraints, potentially leading to the copying or writing of files outside the designated installation root. This can undermine local filesystem integrity, posing significant security risks. The issue has been addressed in version 2.7.8, which is recommended for all users to ensure secure operation.
Affected Version(s)
mport < 2.7.8
