CVE-2026-54584

CVE-2026-54584 published: mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root or in setuid/setgid contexts. An attacker able to control the environment for a privileged mport invocation could red...

View full NVD advisory → ← Back to CVE watch