CVE-2026-57825
In the opam package before 2.5.2 for OCaml, the sandbox protection mechanism can be bypassed because symlinks are mishandled during use of .install files.
- Published Sep 9, 2026
- CVSS 5.7 medium
- 0.5% chance of exploitation in the next 30 days (EPSS)
- A fix is available