Directory Traversal Vulnerability in OCaml opam Software
CVE-2026-41082
7.3HIGH
What is CVE-2026-41082?
A directory traversal vulnerability exists in OCaml opam versions before 2.5.1, where a maliciously crafted .install file can exploit the destination filepath using ../ sequences. This may allow unauthorized access to files outside the intended directory, potentially leading to data exposure or manipulation.
Affected Version(s)
opam 0 < 2.5.1
