CVE-2026-57825

Summary

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

Affected Software

VendorProductVersion RangeStatus
OCamlopam0 < 2.5.2affected

Weaknesses

  • CWE-61: CWE-61 UNIX Symbolic Link (Symlink) Following

ADP Enrichment

CVE Program Container

Additional References

References