A malicious or compromised MacPorts mirror can execute arbitrary commands as root on the machine of a client running port selfupdate against the mirror.
- https://github.com/google/security-research/security/advisories/GHSA-2j38-pjh8-wfxw
No PoCs found on GitHub currently.