CVE-2026-57825
5.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N
Summary
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OCaml | opam | 0 < 2.5.2 | affected |
Weaknesses
- CWE-61: CWE-61 UNIX Symbolic Link (Symlink) Following
ADP Enrichment
CVE Program Container
Additional References
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.