Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41082

Опубликовано: 16 апр. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

A flaw was found in OCaml opam. A malicious package containing a crafted .install field with directory traversal sequences allows an attacker to write files to arbitrary locations, potentially overwriting system files and causing arbitrary code execution.

Отчет

To exploit this flaw, an attacker must convince a user to install a malicious package with a specially crafted .install field. Due to this reason, this vulnerability has been rated with an important severity.

Меры по смягчению последствий

To mitigate this vulnerability, do not install packages from untrusted sources and manually inspect the .install field in the package source to make sure it does not contain malicious paths.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ocaml-duneAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-24
https://bugzilla.redhat.com/show_bug.cgi?id=2459003ocaml-opam: path traversal via the .install field

EPSS

Процентиль: 11%
0.00205
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

CVSS3: 7.3
nvd
4 месяца назад

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

msrc
3 месяца назад

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

CVSS3: 7.3
debian
4 месяца назад

In OCaml opam before 2.5.1, a .install field containing a destination ...

CVSS3: 7.3
github
4 месяца назад

In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.

EPSS

Процентиль: 11%
0.00205
Низкий

7.1 High

CVSS3