Sandbox Bypass Vulnerability in OCaml's opam Package
CVE-2026-57825
5.7MEDIUM
What is CVE-2026-57825?
The opam package for OCaml prior to version 2.5.2 contains a significant flaw in its sandbox protection mechanism, which allows an attacker to bypass intended security restrictions. This is primarily due to improper handling of symbolic links during the processing of .install files, potentially leading to unauthorized access to critical system resources. Users of affected versions are urged to upgrade to mitigate associated risks.
Affected Version(s)
opam 0 < 2.5.2
