CVE-2026-41082

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-16 18:16

Updated : 2026-07-15 02:21


NVD link : CVE-2026-41082

Mitre link : CVE-2026-41082

CVE.ORG link : CVE-2026-41082


JSON object : View

Products Affected

redhat

  • enterprise_linux

ocaml

  • opam

debian

  • debian_linux
CWE
CWE-24

Path Traversal: '../filedir'

CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')