Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.3

Opam Allow Path Traversal When Installing Packages

CVE-2026-41082
Summary

Opam, a package manager for OCaml, contains a flaw that allows attackers to install packages in unintended locations. This could lead to malicious code being installed on a system. Update to a version of Opam 2.5.1 or later to fix this issue.

Original title
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Original description
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
nvd CVSS3.1 7.3
Vulnerability type
CWE-24
Published: 16 Apr 2026 · Updated: 16 Apr 2026 · First seen: 16 Apr 2026