CVE-2026-57825: Medium severity opam/OCaml vulnerability
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
opam (OCaml)to a version that resolves this vulnerability.Fixed in 2.5.2
Event History
Frequently Asked Questions
What access and user interaction are required for exploitation?
The attack vector is network-based, requires low privileges, and requires user interaction. The vulnerability affects handling of .install files, so exploitation depends on a user processing a crafted package installation scenario.
Which versions are affected?
opam versions before 2.5.2 are affected. Updating to opam 2.5.2 or later addresses the vulnerable version range.
What security impact does a successful exploit have?
The reported impact is integrity-only and rated high for integrity. Confidentiality and availability impacts are reported as none.