CVE-2026-54584Medium· 5.3▾ Sunlitmport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could redirect temporary metadata extraction to an attacker-controlled location. PR 123 ignores unsafe TMPDIR values in privileged contexts and rejects empty TMPDIR. This issue has been patched in version 2.7.8.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-54582Medium· 6.0mport is the MidnightBSD Package Manager
CVE-2026-54583High· 8.3mport is the MidnightBSD Package Manager
CVE-2026-54585Medium· 6.0mport is the MidnightBSD Package Manager
CVE-2026-54586Medium· 6.0mport is the MidnightBSD Package Manager
CVE-2026-54587Medium· 5.8mport is the MidnightBSD Package Manager
CVE-2026-54581High· 8.3mport is the MidnightBSD Package Manager