CVE-2024-11681
A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
More information : https://github.com/google/security-research/security/advisories/GHSA-2j38-pjh8-wfxw