CVE-2026-41082
published 2026-04-16CVE-2026-41082: In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
PriorityP337high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.21%
10.6th percentile
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| ocaml | opam | < 2.5.1 | 2.5.1 |
| redhat | enterprise_linux | — | — |
| ubuntu | opam | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
opam vulnerability
vendor_ubuntu·2026-05-07
CVE-2026-41082 opam vulnerability
Title: opam vulnerability
Summary: opam could be made to install files in unintended locations if it installed
a specially crafted package.
Andrew Nesbitt discovered that opam did not properly validate file
destination paths in package install files. An attacker could use this
issue to bypass sandbox protections and write files to arbitrary locations,
possibly leading to arbitrary code execution.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ocaml-opam: path traversal via the .install field
vendor_redhat·2026-04-16·CVSS 7.3
CVE-2026-41082 [HIGH] CWE-24 ocaml-opam: path traversal via the .install field
ocaml-opam: path traversal via the .install field
A flaw was found in OCaml opam. A malicious package containing a crafted .install field with directory traversal sequences allows an attacker to write files to arbitrary locations, potentially overwriting system files and causing arbitrary code execution.
Statement: To exploit this flaw, an attacker must convince a user to install a malicious package with a specially crafted .install field. Due to this reason, this vulnerability has been rated with an important severity.
Mitigation: To mitigate this vulnerability, do not install packages from untrusted sources and manually inspect the .install field in the package source to make sure it does not contain malicious paths.
Package: ocaml-dune (Red Hat Enterprise Linux 10) - Affected
GHSA
GHSA-97q5-qf47-hvrw: In OCaml opam before 2
ghsa_unreviewed·2026-04-16
CVE-2026-41082 [HIGH] CWE-24 GHSA-97q5-qf47-hvrw: In OCaml opam before 2
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
VulDB
OCaml opam up to 2.5.0 Destination install path traversal (EUVD-2026-23288)
vuldb·2026-04-16·CVSS 7.3
CVE-2026-41082 [HIGH] OCaml opam up to 2.5.0 Destination install path traversal (EUVD-2026-23288)
A vulnerability identified as problematic has been detected in OCaml opam up to 2.5.0. Affected is an unknown function of the component Destination Handler. This manipulation of the argument install causes path traversal: '../filedir'.
This vulnerability is handled as CVE-2026-41082. It is possible to launch the attack on the local host. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41082 ocaml-dune: path traversal via the .install field [fedora-all]
bugzilla·2026-04-17·CVSS 7.3
CVE-2026-41082 [HIGH] CVE-2026-41082 ocaml-dune: path traversal via the .install field [fedora-all]
CVE-2026-41082 ocaml-dune: path traversal via the .install field [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41082 ocaml-opam: path traversal via the .install field
bugzilla·2026-04-16·CVSS 7.3
CVE-2026-41082 [HIGH] CVE-2026-41082 ocaml-opam: path traversal via the .install field
CVE-2026-41082 ocaml-opam: path traversal via the .install field
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
https://github.com/ocaml/opam/pull/6897https://github.com/ocaml/opam/releases/tag/2.5.1https://osv.dev/vulnerability/OSEC-2026-03https://lists.debian.org/debian-lts-announce/2026/04/msg00021.htmlhttps://access.redhat.com/security/cve/CVE-2026-41082https://bugzilla.redhat.com/show_bug.cgi?id=2459003https://osv.dev/vulnerability/OSEC-2026-03https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json
2026-04-16
Published