Junglewise Threat Intelligence

CVE-2026-41082: OCaml opam path traversal in .install field

CVE-2026-41082 · Severity: high · CVSS 7.3 · Published 2026-04-16

Vendors: OCaml.

Executive brief

OCaml opam is a package manager used to install and manage software libraries. A security flaw in how it handles installation instructions allows a malicious package to write files outside of its intended directory. This could allow an attacker to overwrite sensitive system files, such as configuration files, potentially leading to unauthorized system access or persistent control over a user's environment.

Technical details

A path traversal vulnerability exists in OCaml opam's handling of .install files. The root cause is insufficient validation of the destination filepath in the .install field, which allows the use of parent directory references (../) to escape the intended package area. An attacker can exploit this by crafting a malicious package that, when installed, writes files to sensitive locations (e.g., overwriting ~/.bashrc). While the opam manual explicitly forbids absolute paths and parent directory references, the software failed to enforce these restrictions prior to version 2.5.1. The vulnerability is fixed in version 2.5.1 and backported to older supported versions in various distributions.

Affected products

  • OCaml opam < 2.5.1
  • OCaml opam-devel < 2.5.1

Timeline

  • 2026-04-11: other: Issue reported to OCaml security team
  • 2026-04-15: patched: opam 2.5.1 released with fix
  • 2026-04-16: disclosed: CVE-2026-41082 published
  • 2026-04-21: advisory: Debian LTS advisory DLA-4541-1 published

References

Related threats