CVE-2026-57825: CWE-61 UNIX Symbolic Link (Symlink) Following in OCaml opam
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
AI Analysis
Technical Summary
In opam versions prior to 2.5.2, the sandbox protection mechanism can be bypassed because symbolic links are mishandled during the processing of .install files. This vulnerability is categorized under CWE-61 (UNIX Symbolic Link Following). The flaw allows an attacker with low privileges and requiring user interaction to cause an integrity impact, as indicated by the CVSS vector (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). No patch or official remediation level is currently confirmed from the vendor advisory or other sources.
Potential Impact
The vulnerability impacts the integrity of the system by allowing sandbox bypass through symbolic link mishandling. Confidentiality and availability are not affected. Exploitation requires network access, low complexity, low privileges, and user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution when processing .install files in opam and consider restricting untrusted package sources or sandbox usage. No official remediation or temporary fix has been documented.
CVE-2026-57825: CWE-61 UNIX Symbolic Link (Symlink) Following in OCaml opam
Description
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
CVSS v3.1
Score 5.7medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In opam versions prior to 2.5.2, the sandbox protection mechanism can be bypassed because symbolic links are mishandled during the processing of .install files. This vulnerability is categorized under CWE-61 (UNIX Symbolic Link Following). The flaw allows an attacker with low privileges and requiring user interaction to cause an integrity impact, as indicated by the CVSS vector (AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:N). No patch or official remediation level is currently confirmed from the vendor advisory or other sources.
Potential Impact
The vulnerability impacts the integrity of the system by allowing sandbox bypass through symbolic link mishandling. Confidentiality and availability are not affected. Exploitation requires network access, low complexity, low privileges, and user interaction. There are no known exploits in the wild at this time.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should exercise caution when processing .install files in opam and consider restricting untrusted package sources or sandbox usage. No official remediation or temporary fix has been documented.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-25T00:00:00.000Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa0d80cacd9273b49ac6fc4
Added to database: 09/09/2026, 03:52:44 UTC
Last enriched: 09/09/2026, 04:07:57 UTC
Last updated: 09/09/2026, 22:52:12 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.