mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-22",
"CWE-73"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54583.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54583.json"
[
{
"deprecated": false,
"digest": {
"function_hash": "312557077777709224098664311619371281642",
"length": 1204
},
"id": "CVE-2026-54583-3b64c0bb",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8",
"target": {
"file": "libmport/fetch.c",
"function": "mport_fetch_bundle"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "279926240390260471795095752599604250445",
"length": 2615
},
"id": "CVE-2026-54583-444194f3",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8",
"target": {
"file": "libmport/fetch.c",
"function": "fetch_bundle_to_dir"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "77786979120203311337767023585829608852",
"length": 2588
},
"id": "CVE-2026-54583-60beb700",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8",
"target": {
"file": "libmport/fetch.c",
"function": "mport_download"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"87202371787256375580825701242587534325",
"155847631730882067225785132318137682222",
"16969444422941396046712201812643089512",
"53629141616247340439864868972216418226",
"155889219455934260419778683542534910943",
"296475452426961737068978726791080226325",
"144275857773958635689974486116846455074",
"190533071917964187748490394958361389761",
"270526375459865402789123927490195747624",
"99674091213720280776695732701223051925",
"239307231278942182362496221019211759861",
"230090929692779450294943475343383081522",
"161514634138263650237184327285810481626",
"148809881244612132829513324690679995279",
"22779278957697872161142995555340380579",
"40805977343552846964737442849581211710",
"289900608927810582569807365384978561596"
],
"threshold": 0.9
},
"id": "CVE-2026-54583-8ab50df3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/cad959d47bc79a62b6a7163800fbfe35633e7cf8",
"target": {
"file": "libmport/fetch.c"
}
}
]
"2026-09-19T08:08:53Z"