Description:
In OCaml opam before 2.5.1, a .install field containing a destination
filepath can use ../ to reach a parent directory. (CVE-2026-41082)
- https://bugs.mageia.org/show_bug.cgi?id=35405
- https://lists.debian.org/debian-security-announce/2026/msg00126.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41082
- 9/core/opam-2.1.3-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.