CVE-2026-57825 Details
Description
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
A vulnerability in the OPAM package manager for OCaml, present in versions prior to 2.5.2, allows for sandbox protection to be bypassed. This issue arises because symlinks are improperly handled when using .install files, enabling a form of directory traversal out of the package area. The vulnerability can be exploited by creating a symlink that points to an external directory, such as the user's home directory, and then using this link to install files outside the intended scope.
Users can upgrade to OPAM version 2.5.2 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 9, 2026CISA-ADP
Assessed Sep 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2026/07/msg00026.html | CVE | AdvisoryMailing ListRemedy |
| https://github.com/ocaml/opam/releases | [email protected] | Release NotesVendor |
| https://osv.dev/vulnerability/OSEC-2026-10 | [email protected] | AdvisoryExploitRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-61 | UNIX Symbolic Link (Symlink) Following | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| OCaml opam | < 2.5.2 (semver) |
CPE
Remediation
| |
| Debian | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 14, 2026 | CVE Modified | CISA-ADP |
| Sep 9, 2026 | CVE Modified | CVE |
| Sep 9, 2026 | New CVE Received | [email protected] |
Volerion