Impact
The vulnerability involves a flaw in opam's sandbox protection where symlinks are mishandled during the processing of .install files, allowing an attacker to bypass the sandbox. This can enable the execution of arbitrary commands or code within the context of the user installing the package. The weakness corresponds to CWE‑61, a form of path or link traversal that compromises access control.
Affected Systems
The bug affects the OCaml opam package manager prior to version 2.5.2. No precise version list is provided, so all releases before 2.5.2 should be considered vulnerable until patched by the vendor.
Risk and Exploitability
The severity score of 5.7 indicates moderate risk. EPSS is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of exploitation. The most likely attack scenario is during the installation of a package containing a malicious .install file; the attacker would need to supply or influence the package contents to exploit the sandbox bypass. Once the sandbox is bypassed, the attacker could achieve privileges equivalent to the user performing the install.
OpenCVE Enrichment
Debian DLA
Debian DSA