> USN-8256-1: opam vulnerability
[DATE: 07/05/2026 15:21]
[LANGUAGE: EN]
Andrew Nesbitt discovered that opam did not properly validate file
destination paths in package install files. An attacker could use this
issue to bypass sandbox protections and write files to arbitrary locations,
possibly leading to arbitrary code execution.