Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41082

27
FAUCET Score

CVE-2026-41082 is a path traversal vulnerability in OCaml opam package manager versions prior to 2.5.1, where malicious .install files can use relative path traversal (../) sequences to write files to parent directories outside the intended installation location. This vulnerability affects the opam package management system used in OCaml development environments. The flaw has a CVSS score of 7.3 (HIGH) with a local attack vector, low complexity, and no privilege or user interaction required, resulting in low confidentiality impact, high integrity impact, and low availability impact. There is no evidence of active exploitation at this time, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score of 0.00006. Users should upgrade to opam 2.5.1 or later to remediate this issue, though the low exploitation probability suggests it is not currently a widespread threat in the wild.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.5.1CPE matchmatch criteria
cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:*
11.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
>= 0, < 2.5.1CPE match
cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.3HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.5
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.21%
Probability of exploitation in next 30 days
EPSS Percentile
10.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0021 is in the 9th percentile among its peer group of 11,621 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
ubuntupatch availablevia ubuntu_usn
Product: opam (focal)Fixed in: 2.0.5-1ubuntu1+esm1
ubuntupatch availablevia ubuntu_usn
Product: opam (jammy)Fixed in: 2.1.2-1+deb12u1build0.22.04.1
ubuntupatch availablevia ubuntu_usn
Product: opam (noble)Fixed in: 2.1.5-1ubuntu0.1~esm2
ubuntupatch availablevia ubuntu_usn
Product: opam (questing)Fixed in: 2.3.0-1+deb13u1build0.25.10.1
ubuntupatch availablevia ubuntu_usn
Product: opam (resolute)Fixed in: 2.5.0-1ubuntu0.1~esm1

Vendor Advisories (2)

ubuntuUSN-8256-1

opam vulnerability

May 7, 2026
microsoft2026-Apr/CVE-2026-41082Important

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

Apr 14, 2026

References

access.redhat.com / security/cve/CVE-2026-41082
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41082.json
Third Party Advisory
lists.debian.org / debian-lts-announce/2026/04/msg00021.html
Mailing ListThird Party Advisory
github.com / ocaml/opam/pull/6897
Issue TrackingPatch
github.com / ocaml/opam/releases/tag/2.5.1
Release Notes
osv.dev / vulnerability/OSEC-2026-03
Third Party Advisory