PT-2026-39181 · Opam-Doc+2 · Opam-Doc+2

Published

2026-05-07

·

Updated

2026-05-07

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions opam versions prior to 2.0.5-1ubuntu1+esm1 opam-doc versions prior to 2.0.5-1ubuntu1+esm1 opam-installer versions prior to 2.0.5-1ubuntu1+esm1
Description Insufficient validation of file destination paths in package install files allows an attacker to bypass sandbox protections. This can enable writing files to arbitrary locations, which may lead to arbitrary code execution.
Recommendations Update to version 2.0.5-1ubuntu1+esm1.

Related Identifiers

USN-8256-1

Affected Products

Opam
Opam-Doc
Opam-Installer