CVE-2026-54587
— UNSCOREDpublic exploit availablePublished 2026-09-17 · Updated 2026-09-17
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
mport is the MidnightBSD Package Manager. Prior to 2.7.8, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE in libmport/bundle_read_install_pkg.c used path-based mport_mkdirp(), ownership, and permission operations. A local attacker able to modify part of the target installation tree could use dot-dot traversal or substitute symlinks during privileged package installation, causing directory creation or attribute changes to affect attacker-selected paths outside the intended package directories. This issue is fixed in version 2.7.8.
Weaknesses
CWE-59, CWE-367
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-54576PoC
- MEDIUMCVE-2026-86861PoC
- HIGHCVE-2026-100419PoC
- HIGHCVE-2026-100597PoC
- HIGHCVE-2026-100690PoC
- HIGHCVE-2026-100692PoC
- HIGHCVE-2026-100713PoC
- CRITICALCVE-2026-100715PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.