ocaml-opam: path traversal via the .install field
Published Apr 16, 2026
7.8
HIGHCVSS 3.1
EPSS 0.22%
Description
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Affected products
-
- Version 0StatusaffectedConstraints<2.5.1
- Version
Configuration 2
- 11.0
Configuration 3
- 10.0
No data.
Red Hat Enterprise Linux 10
ocaml-dune
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | ocaml-dune | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
To exploit this flaw, an attacker must convince a user to install a malicious package with a specially crafted .install field. Due to this reason, this vulnerability has been rated with an important severity.
Red Hat mitigation
To mitigate this vulnerability, do not install packages from untrusted sources and manually inspect the .install field in the package source to make sure it does not contain malicious paths.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
2 other sources (MITRE, Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jun 16, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.22% (0.00216) | 10.87th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.18% (0.00183) | 7.99th | v5 (v2026.06.15) |
| Apr 17, 2026 | 0.01% (0.00005) | 0.25th | v4 (v2025.03.14) |
References (9)
- https://access.redhat.com/security/cve/CVE-2026-41082 Third Party AdvisoryVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2459003 Issue Tracking
- https://github.com/ocaml/opam/pull/6897 Issue TrackingPatch
- https://github.com/ocaml/opam/releases/tag/2.5.1 Release Notes
- https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html Mailing ListThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41082
- https://osv.dev/vulnerability/OSEC-2026-03 exploitThird Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-41082
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41082 | Third Party AdvisoryVendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2459003 | Issue Tracking | |
| https://github.com/ocaml/opam/pull/6897 | Issue TrackingPatch | |
| https://github.com/ocaml/opam/releases/tag/2.5.1 | Release Notes | |
| https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html | Mailing ListThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41082 | ||
| https://osv.dev/vulnerability/OSEC-2026-03 | exploitThird Party Advisory | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json | Third Party Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-41082 |
Change history (0)
No recorded changes yet.