CVE-2026-57825Medium· 5.7▾ SunlitIn the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 31.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 10.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41082High· 7.3In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
CVE-2026-87734High· 7.5An issue was discovered in the utcp package before 0.0.6 for OCaml
CVE-2026-89086Critical· 9.1In the jose package before 0.11.0 for OCaml, library calls to validate an RSA signature only confirm that PKCS #1 decoding succeeds, and proceed to declare the signature valid without the required steps that involve the public key.
CVE-2026-87736Medium· 4.3An issue was discovered in the mirage-crypto-ec package before 2.3.0 for OCaml
CVE-2026-89087High· 7.3The cstruct package before 6.3.0 for OCaml mishandles indexes.
CVE-2026-87735Medium· 4.3An issue was discovered in the mirage-crypto-pk package before 2.3.0 for OCaml