In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
References
| Link | Resource |
|---|---|
| https://github.com/ocaml/opam/pull/6897 | Issue Tracking Patch |
| https://github.com/ocaml/opam/releases/tag/2.5.1 | Release Notes |
| https://osv.dev/vulnerability/OSEC-2026-03 | Third Party Advisory |
| https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html | Mailing List Third Party Advisory |
| https://access.redhat.com/security/cve/CVE-2026-41082 | Third Party Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2459003 | Issue Tracking |
| https://osv.dev/vulnerability/OSEC-2026-03 | Third Party Advisory |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json | Third Party Advisory |
Configurations
History
08 Jul 2026, 03:29
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Debian
Debian debian Linux Redhat enterprise Linux Redhat Ocaml Ocaml opam |
|
| CPE | cpe:2.3:a:ocaml:opam:*:*:*:*:*:*:*:* cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:* |
|
| CWE | CWE-22 | |
| References | () https://github.com/ocaml/opam/pull/6897 - Issue Tracking, Patch | |
| References | () https://github.com/ocaml/opam/releases/tag/2.5.1 - Release Notes | |
| References | () https://osv.dev/vulnerability/OSEC-2026-03 - Third Party Advisory | |
| References | () https://lists.debian.org/debian-lts-announce/2026/04/msg00021.html - Mailing List, Third Party Advisory | |
| References | () https://access.redhat.com/security/cve/CVE-2026-41082 - Third Party Advisory | |
| References | () https://bugzilla.redhat.com/show_bug.cgi?id=2459003 - Issue Tracking | |
| References | () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41082.json - Third Party Advisory |
30 Jun 2026, 03:19
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Jun 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://osv.dev/vulnerability/OSEC-2026-03 - |
15 Jun 2026, 20:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Apr 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
16 Apr 2026, 18:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-16 18:16
Updated : 2026-07-15 02:21
NVD link : CVE-2026-41082
Mitre link : CVE-2026-41082
CVE.ORG link : CVE-2026-41082
JSON object : View
Products Affected
ocaml
- opam
debian
- debian_linux
redhat
- enterprise_linux
