High severity7.3NVD Advisory· Published Apr 16, 2026· Updated Jul 15, 2026
CVE-2026-41082
CVE-2026-41082
Description
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
- osv-coords2 versionspkg:rpm/opensuse/opam&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/opam&distro=openSUSE%20Tumbleweed
< 2.5.2-bp160.1.1+ 1 more
- (no CPE)range: < 2.5.2-bp160.1.1
- (no CPE)range: < 2.5.1-1.1
Patches
Vulnerability mechanics
References
7- github.com/ocaml/opam/pull/6897nvdIssue TrackingPatch
- access.redhat.com/security/cve/CVE-2026-41082nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2026/04/msg00021.htmlnvdMailing ListThird Party Advisory
- osv.dev/vulnerability/OSEC-2026-03nvdThird Party Advisory
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.jsonnvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- github.com/ocaml/opam/releases/tag/2.5.1nvdRelease Notes
News mentions
0No linked articles in our index yet.