Back

HIGH

ocaml-opam: path traversal via the .install field

Published Apr 16, 2026

Description

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Affected products

Remediation

Red Hat statement

To exploit this flaw, an attacker must convince a user to install a malicious package with a specially crafted .install field. Due to this reason, this vulnerability has been rated with an important severity.

Red Hat mitigation

To mitigate this vulnerability, do not install packages from untrusted sources and manually inspect the .install field in the package source to make sure it does not contain malicious paths.

Metrics

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Apr 16, 2026
Updated Jul 15, 2026
Reserved Apr 16, 2026
CISA Vulnrichment
Updated Jun 16, 2026
NVD
Status Analyzed
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Apr 16, 2026