CVE-2026-57825
Deferred Deferred - Pending Action

OPAM Package Symlink Bypass Vulnerability

Vulnerability report for CVE-2026-57825, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ocaml opam to 2.5.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-61 The product, when opening a file or directory, does not sufficiently account for when the file is a symbolic link that resolves to a target outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in the opam package manager for OCaml before version 2.5.2. The issue allows bypassing sandbox protection by mishandling symlinks during the use of .install files. This could let an attacker manipulate file operations outside the intended sandboxed environment.

Detection Guidance

To detect this vulnerability, check the installed version of opam on your system. If it is below 2.5.2, the system is vulnerable. Use the command 'opam --version' to check the version.

Impact Analysis

If exploited, this vulnerability could allow an attacker with limited privileges to write files outside the sandbox, potentially leading to unauthorized code execution, data tampering, or privilege escalation. Users relying on opam for OCaml package management may face compromised system integrity or confidentiality.

Compliance Impact

This vulnerability could impact compliance by enabling unauthorized data access or modification, violating integrity and confidentiality requirements in GDPR and HIPAA. Organizations using affected opam versions may fail audits or face penalties due to inadequate sandboxing controls.

Mitigation Strategies

Update the opam package to version 2.5.2 or later to address the symlink handling issue in .install files. Verify the installed version with 'opam --version' and check for any suspicious .install files in package directories.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57825. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart