Home
HIGH: 7.3 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:LDefault status
unaffected
Any version before 2.5.1
affected
Description
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Problem types
CWE-24 Path Traversal: '../filedir'
Product status
Any version before 2.5.1
References
lists.debian.org/debian-lts-announce/2026/04/msg00021.html
github.com/ocaml/opam/releases/tag/2.5.1
github.com/ocaml/opam/pull/6897