Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.3
Opam Allow Path Traversal When Installing Packages
CVE-2026-41082
Summary
Opam, a package manager for OCaml, contains a flaw that allows attackers to install packages in unintended locations. This could lead to malicious code being installed on a system. Update to a version of Opam 2.5.1 or later to fix this issue.
Original title
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Original description
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
nvd CVSS3.1
7.3
Vulnerability type
CWE-24
Published: 16 Apr 2026 · Updated: 16 Apr 2026 · First seen: 16 Apr 2026