mport is the MidnightBSD Package Manager. Prior to 2.7.8, create_sample_file() in libmport/bundle_read_install_pkg.c did not constrain absolute source and destination paths from the sample-file manifest directive to mport->root. A malicious or malformed package manifest could therefore direct privileged sample-file handling to copy or write outside the configured installation root, compromising local filesystem integrity. This issue is fixed in version 2.7.8.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-22"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54585.json"
}"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54585.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"236029657467675296629030037393227001166",
"260839329948985946908815546951352072992",
"306309436848299513975217031919783395689",
"220026163161831257632691399852254961875",
"338848387342946539516354401943299562244",
"129514344371739286279638810802721641975",
"47537408416916947704041599510808272154",
"291508972028700745498570652367299301934"
],
"threshold": 0.9
},
"id": "CVE-2026-54585-341cd73a",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/36a42c8ddbd23ee9eb72c4c17596eb92cb423cf0",
"target": {
"file": "libmport/bundle_read_install_pkg.c"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "319263696170093865883928250513563263123",
"length": 1066
},
"id": "CVE-2026-54585-e78fda46",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/midnightbsd/mport/commit/36a42c8ddbd23ee9eb72c4c17596eb92cb423cf0",
"target": {
"file": "libmport/bundle_read_install_pkg.c",
"function": "create_sample_file"
}
}
]
"2026-09-19T08:08:53Z"