opam vulnerabilities
CVEs whose affected-version data names the opam package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-57825Medium· 5.7In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
▾ SunlitOCaml · opamEPSS 0.31%via NVD
CVE-2026-41082High· 7.3In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
▾ Twilightocaml · opamEPSS 0.21%via NVD