Sandbox Bypass Vulnerability in OCaml's opam Package
CVE-2026-57825

5.7MEDIUM

Key Information:

Vendor

Ocaml

Status
Vendor
CVE Published:
9 September 2026

What is CVE-2026-57825?

The opam package for OCaml prior to version 2.5.2 contains a significant flaw in its sandbox protection mechanism, which allows an attacker to bypass intended security restrictions. This is primarily due to improper handling of symbolic links during the processing of .install files, potentially leading to unauthorized access to critical system resources. Users of affected versions are urged to upgrade to mitigate associated risks.

Affected Version(s)

opam 0 < 2.5.2

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.