
CVE-2026-41082 In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory. https://www.cve.org/CVERecord?id=CVE-2026-41082
Post summary
A directory‑traversal vulnerability (CVE‑2026‑41082) is disclosed for OCaml opam versions prior to 2.5.1, where the .install field can use '..' to reach parent directories.

