Andrew Nesbitt discovered that opam did not properly validate file
destination paths in package install files. An attacker could use this
issue to bypass sandbox protections and write files to arbitrary locations,
possibly leading to arbitrary code execution.
Intelligence View
⚡ tsecurity.de Intelligence
USN-8256-1: opam vulnerability
Andrew Nesbitt discovered that opam did not properly validate file destination paths in package install files. An attacker could use this issue to bypass…