Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-4541-1 | opam security update |
Debian DSA |
DSA-6216-1 | opam security update |
Tue, 21 Apr 2026 10:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 18 Apr 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in opam .install Files Enables Arbitrary File Modification | ocaml-opam: path traversal via the .install field |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 17 Apr 2026 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ocaml
Ocaml ocaml |
|
| Vendors & Products |
Ocaml
Ocaml ocaml |
Fri, 17 Apr 2026 03:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Path Traversal in opam .install Files Enables Arbitrary File Modification |
Thu, 16 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Apr 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. | |
| Weaknesses | CWE-24 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-21T09:32:52.152Z
Reserved: 2026-04-16T17:32:39.584Z
Link: CVE-2026-41082
Updated: 2026-04-21T09:32:52.152Z
Status : Awaiting Analysis
Published: 2026-04-16T18:16:45.980
Modified: 2026-04-21T10:16:31.107
Link: CVE-2026-41082
OpenCVE Enrichment
Updated: 2026-04-17T08:00:10Z
Debian DLA
Debian DSA