CVE-2026-54584: CWE-73: External Control of File Name or Path in MidnightBSD mport
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.
AI Analysis
Technical Summary
MidnightBSD's mport package manager versions before 2.7.8 used the TMPDIR environment variable when extracting package metafiles, including during privileged operations such as running as root or in setuid/setgid contexts. An attacker with the ability to influence the environment of a privileged mport invocation could exploit this to redirect temporary metadata extraction to an attacker-controlled path. The patch in version 2.7.8 addresses this by ignoring unsafe TMPDIR values in privileged contexts and rejecting empty TMPDIR values, mitigating the risk of external control of file name or path (CWE-73).
Potential Impact
An attacker able to control the environment for a privileged mport execution could redirect temporary file extraction to an attacker-controlled location, potentially leading to unauthorized file manipulation or privilege escalation. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges required, and limited confidentiality impact.
Mitigation Recommendations
Upgrade mport to version 2.7.8 or later, where the vulnerability has been patched by ignoring unsafe TMPDIR environment variable values in privileged contexts and rejecting empty TMPDIR. No other mitigation is required as the issue is fixed in the official release.
CVE-2026-54584: CWE-73: External Control of File Name or Path in MidnightBSD mport
Description
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.
CVSS v4.0
Score 5.3medium
Affected software
MidnightBSD
mport
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
MidnightBSD's mport package manager versions before 2.7.8 used the TMPDIR environment variable when extracting package metafiles, including during privileged operations such as running as root or in setuid/setgid contexts. An attacker with the ability to influence the environment of a privileged mport invocation could exploit this to redirect temporary metadata extraction to an attacker-controlled path. The patch in version 2.7.8 addresses this by ignoring unsafe TMPDIR values in privileged contexts and rejecting empty TMPDIR values, mitigating the risk of external control of file name or path (CWE-73).
Potential Impact
An attacker able to control the environment for a privileged mport execution could redirect temporary file extraction to an attacker-controlled location, potentially leading to unauthorized file manipulation or privilege escalation. The CVSS 4.0 base score is 5.3 (medium severity), reflecting network attack vector, low complexity, no privileges required, and limited confidentiality impact.
Mitigation Recommendations
Upgrade mport to version 2.7.8 or later, where the vulnerability has been patched by ignoring unsafe TMPDIR environment variable values in privileged contexts and rejecting empty TMPDIR. No other mitigation is required as the issue is fixed in the official release.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T19:15:27.344Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ab13ff155bf5e2cf5064d25
Added to database: 09/21/2026, 14:32:17 UTC
Last enriched: 09/21/2026, 14:46:59 UTC
Last updated: 09/21/2026, 23:29:55 UTC
Views: 11
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.