rpm package
opensuse/opam&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/opam&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-57825 | Med | 5.7 | < 2.5.2-1.2 | 2.5.2-1.2 | Sep 9, 2026 | In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files. | |
| CVE-2026-41082 | Hig | 7.3 | < 2.5.1-1.1 | 2.5.1-1.1 | Apr 16, 2026 | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. |
- affected < 2.5.2-1.2fixed 2.5.2-1.2
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
- affected < 2.5.1-1.1fixed 2.5.1-1.1
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.