CVE-2026-54587: CWE-59: Improper Link Resolution Before File Access ('Link Following') in MidnightBSD mport
CVE-2026-54587 is a vulnerability in the MidnightBSD package manager 'mport' prior to version 2.7.8. It involves improper link resolution before file access, allowing a local attacker with limited privileges to manipulate directory creation or attribute changes during privileged package installation. This is achieved by exploiting dot-dot traversal or symlink substitution to affect paths outside the intended package directories. The issue is fixed in version 2.7.8.
AI Analysis
Technical Summary
The vulnerability in mport versions before 2.7.8 arises from handling directory assets with path-based operations that do not properly resolve symbolic links or prevent directory traversal. Specifically, in libmport/bundle_read_install_pkg.c, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE use mport_mkdirp() and related ownership and permission operations based on paths that can be manipulated by a local attacker. This allows the attacker to cause directory creation or attribute changes outside the intended package installation directories during privileged package installation, potentially leading to unauthorized modifications of the filesystem.
Potential Impact
A local attacker with the ability to modify part of the target installation tree can exploit this vulnerability to cause directory creation or attribute changes outside the intended package directories during privileged package installation. This could lead to unauthorized filesystem modifications, potentially affecting system integrity or security. The CVSS 4.0 score is 5.8 (medium severity), reflecting the need for local access with high attack complexity and partial impact on integrity and availability.
Mitigation Recommendations
This vulnerability is fixed in MidnightBSD mport version 2.7.8. Users should upgrade to version 2.7.8 or later to remediate this issue. No additional vendor advisory or patch links are provided, but upgrading to the fixed version is the recommended action.
CVE-2026-54587: CWE-59: Improper Link Resolution Before File Access ('Link Following') in MidnightBSD mport
Description
CVE-2026-54587 is a vulnerability in the MidnightBSD package manager 'mport' prior to version 2.7.8. It involves improper link resolution before file access, allowing a local attacker with limited privileges to manipulate directory creation or attribute changes during privileged package installation. This is achieved by exploiting dot-dot traversal or symlink substitution to affect paths outside the intended package directories. The issue is fixed in version 2.7.8.
CVSS v4.0
Score 5.8medium
Affected software
MidnightBSD
mport
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in mport versions before 2.7.8 arises from handling directory assets with path-based operations that do not properly resolve symbolic links or prevent directory traversal. Specifically, in libmport/bundle_read_install_pkg.c, directory assets handled as ASSET_DIR or ASSET_DIR_OWNER_MODE use mport_mkdirp() and related ownership and permission operations based on paths that can be manipulated by a local attacker. This allows the attacker to cause directory creation or attribute changes outside the intended package installation directories during privileged package installation, potentially leading to unauthorized modifications of the filesystem.
Potential Impact
A local attacker with the ability to modify part of the target installation tree can exploit this vulnerability to cause directory creation or attribute changes outside the intended package directories during privileged package installation. This could lead to unauthorized filesystem modifications, potentially affecting system integrity or security. The CVSS 4.0 score is 5.8 (medium severity), reflecting the need for local access with high attack complexity and partial impact on integrity and availability.
Mitigation Recommendations
This vulnerability is fixed in MidnightBSD mport version 2.7.8. Users should upgrade to version 2.7.8 or later to remediate this issue. No additional vendor advisory or patch links are provided, but upgrading to the fixed version is the recommended action.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-15T19:15:27.345Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6aac405255bf5e2cf5cb238d
Added to database: 09/17/2026, 19:32:34 UTC
Last enriched: 09/17/2026, 19:47:04 UTC
Last updated: 09/17/2026, 19:47:04 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.