Back

HIGH

mport package bundle downloads allow unsafe destination filenames

Published Sep 17, 2026

Description

mport is the MidnightBSD Package Manager. Prior to 2.7.8, libmport/fetch.c did not consistently reject empty, dot, dot-dot, or slash-containing bundle filenames before composing package download and write paths. Malicious package index data could place an unsafe value in indexEntry->bundlefile, and the missing is_valid_bundle_filename() checks allowed downloaded package data to be written outside the intended cache location or to an unsafe destination name. This issue is fixed in version 2.7.8.

Affected products

Remediation

No remediation recorded yet.

References (5)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 17, 2026
Reserved Jun 15, 2026

CISA Vulnrichment

Updated Sep 17, 2026

NVD

Status Deferred
Modified Sep 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Sep 17, 2026
Updated Sep 17, 2026

GitHub

No data