Andrew Nesbitt discovered that opam did not properly validate file destination paths in package install files. An attacker could use this issue to bypass sandbox protections and write files to arbitrary locations, possibly leading to arbitrary code execution.
{
"binaries": [
{
"binary_version": "2.0.5-1ubuntu1+esm1",
"binary_name": "opam"
},
{
"binary_version": "2.0.5-1ubuntu1+esm1",
"binary_name": "opam-installer"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:20.04:LTS",
"cves": [
{
"id": "CVE-2026-41082",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8256-1.json"
{
"binaries": [
{
"binary_version": "2.1.2-1+deb12u1build0.22.04.1",
"binary_name": "opam"
},
{
"binary_version": "2.1.2-1+deb12u1build0.22.04.1",
"binary_name": "opam-installer"
}
],
"availability": "No subscription required"
}
{
"ecosystem": "Ubuntu:22.04:LTS",
"cves": [
{
"id": "CVE-2026-41082",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8256-1.json"
{
"binaries": [
{
"binary_version": "2.1.5-1ubuntu0.1~esm2",
"binary_name": "opam"
},
{
"binary_version": "2.1.5-1ubuntu0.1~esm2",
"binary_name": "opam-installer"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:24.04:LTS",
"cves": [
{
"id": "CVE-2026-41082",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8256-1.json"
{
"binaries": [
{
"binary_version": "2.3.0-1+deb13u1build0.25.10.1",
"binary_name": "opam"
},
{
"binary_version": "2.3.0-1+deb13u1build0.25.10.1",
"binary_name": "opam-installer"
}
],
"availability": "No subscription required"
}
{
"ecosystem": "Ubuntu:25.10",
"cves": [
{
"id": "CVE-2026-41082",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8256-1.json"
{
"binaries": [
{
"binary_version": "2.5.0-1ubuntu0.1~esm1",
"binary_name": "opam"
},
{
"binary_version": "2.5.0-1ubuntu0.1~esm1",
"binary_name": "opam-installer"
}
],
"availability": "Available with Ubuntu Pro: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:26.04:LTS",
"cves": [
{
"id": "CVE-2026-41082",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L"
},
{
"type": "Ubuntu",
"score": "medium"
}
]
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8256-1.json"