cve-2026-57825

MEDIUM CVSS 5.7 nvd
Description

In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.

Timeline
Published
2026-09-09
Last Modified
2026-09-14
CVSS Details
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
Affected Products

No product information available.

Weaknesses (CWE)
CVSS metrics
Version Base Severity Vector Exploitability Impact Source
3.1 5.7 MEDIUM CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N 2.1 3.6 cve@mitre.org
NVD metadata
NVD status
Deferred
Source identifier
cve@mitre.org
References
Linked Vulnerabilities

{
  "cvss": 5.7,
  "datePublished": "2026-09-09T04:18:01.720",
  "dateUpdated": "2026-09-14T16:17:15.167",
  "description": "In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.",
  "id": "CVE-2026-57825",
  "raw": {
    "affected": [
      {
        "affectedData": [
          {
            "defaultStatus": "unaffected",
            "packageURL": "pkg:opam/opam-devel",
            "product": "opam",
            "vendor": "OCaml",
            "versions": [
              {
                "lessThan": "2.5.2",
                "status": "affected",
                "version": "0",
                "versionType": "semver"
              }
            ]
          }
        ],
        "source": "cve@mitre.org"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files."
      }
    ],
    "id": "CVE-2026-57825",
    "lastModified": "2026-09-14T16:17:15.167",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.7,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "HIGH",
            "privilegesRequired": "LOW",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N",
            "version": "3.1"
          },
          "exploitabilityScore": 2.1,
          "impactScore": 3.6,
          "source": "cve@mitre.org",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2026-57825",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "partial"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2026-09-14T15:37:34.957373Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2026-09-09T04:18:01.720",
    "references": [
      {
        "source": "cve@mitre.org",
        "url": "https://github.com/ocaml/opam/releases"
      },
      {
        "source": "cve@mitre.org",
        "url": "https://osv.dev/vulnerability/OSEC-2026-10"
      },
      {
        "source": "af854a3a-2127-422b-91ae-364da2661108",
        "url": "https://lists.debian.org/debian-lts-announce/2026/07/msg00026.html"
      }
    ],
    "sourceIdentifier": "cve@mitre.org",
    "vulnStatus": "Deferred",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-61"
          }
        ],
        "source": "cve@mitre.org",
        "type": "Secondary"
      }
    ]
  },
  "severity": "MEDIUM",
  "source": "nvd",
  "title": "In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mis..."
}
View JSON API Download JSON