CVE-2026-41082: Path Traversal
Published Apr 16, 2026
·Updated
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Affected Software
4 affected components
opam<2.5.1
ocaml opam<2.5.1
Debian Debian Linux=11.0
redhat Enterprise Linux=10.0
Event History
Apr 16, 2026
CVE Published
via MITRE·05:32 PM
Data Sourced
via MITRE·05:32 PM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·06:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·06:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-41082?
CVE-2026-41082 is considered a moderate severity vulnerability affecting OCaml opam versions prior to 2.5.1.
2
How do I fix CVE-2026-41082?
To fix CVE-2026-41082, upgrade OCaml opam to version 2.5.1 or later.
3
What type of vulnerability is CVE-2026-41082?
CVE-2026-41082 is a directory traversal vulnerability that allows the manipulation of file paths.
4
Which versions of OCaml opam are affected by CVE-2026-41082?
CVE-2026-41082 affects all versions of OCaml opam prior to 2.5.1.
5
How can CVE-2026-41082 impact my system?
CVE-2026-41082 can potentially allow an attacker to write files to unintended directories, compromising system integrity.