CVE-2026-41082 is a path traversal vulnerability in OCaml opam package manager versions prior to 2.5.1, where malicious .install files can use relative path traversal (../) sequences to write files to parent directories outside the intended installation location. This vulnerability affects the opam package management system used in OCaml development environments. The flaw has a CVSS score of 7.3 (HIGH) with a local attack vector, low complexity, and no privilege or user interaction required, resulting in low confidentiality impact, high integrity impact, and low availability impact. There is no evidence of active exploitation at this time, as the vulnerability is not listed in the Known Exploited Vulnerabilities catalog and shows minimal community attention with an EPSS score of 0.00006. Users should upgrade to opam 2.5.1 or later to remediate this issue, though the low exploitation probability suggests it is not currently a widespread threat in the wild.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.5.1CPE matchmatch criteria | cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* | ||
>= 0, < 2.5.1CPE match | cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.