{"id":"CVE-2026-57825","title":"In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.","summary":"In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.","severity":"medium","cvss":5.7,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N","cwe":["CWE-61"],"vendor":"OCaml","product":"opam","affected":["opam < 2.5.2"],"published":"2026-09-09","updated":"2026-09-14","sourceUpdated":"2026-09-14T16:17:15.167","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57825","references":[{"url":"https://github.com/ocaml/opam/releases","label":"cve@mitre.org"},{"url":"https://osv.dev/vulnerability/OSEC-2026-10","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2026/07/msg00026.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.00472,"epssPercentile":0.38153,"ingestedAt":"2026-09-14T08:55:47.358Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-14T15:37:34.957373Z"},"slug":"CVE-2026-57825","body":"## Overview\n\nIn the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":31,"depthScoreParts":{"impact":31.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}