7.3 HIGH
- CVSS version: 3.1
- Attack vector (AV): LOCAL
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): HIGH
- Availability impact (A): LOW
by @LeSuisse Activity log
- Created automatic suggestion
-
@LeSuisse
ignored
23 packages
- dopamine
- opam2json
- opam-publish
- opam-installer
- ocamlPackages.opam-core
- ocamlPackages.opam-state
- ocamlPackages.opam-client
- ocamlPackages.opam-format
- ocamlPackages.opam-solver
- ocamlPackages.opam-repository
- ocamlPackages.opam-file-format
- ocamlPackages_latest.opam-core
- ocamlPackages_latest.opam-state
- ocamlPackages.opam-0install-cudf
- ocamlPackages_latest.opam-client
- ocamlPackages_latest.opam-format
- ocamlPackages_latest.opam-solver
- ocamlPackages_latest.opam-repository
- ocamlPackages_latest.opam-file-format
- tree-sitter-grammars.tree-sitter-opam
- ocamlPackages_latest.opam-0install-cudf
- python313Packages.tree-sitter-grammars.tree-sitter-opam
- python314Packages.tree-sitter-grammars.tree-sitter-opam
- @LeSuisse accepted
- @LeSuisse published on GitHub
In OCaml opam before 2.5.1, a .install field containing a …
In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.
Affected products
- <2.5.1
Matching in nixpkgs
Ignored packages (23)
pkgs.dopamine
Audio player that keeps it simple
pkgs.opam2json
Convert opam file syntax to JSON
pkgs.opam-publish
Tool to ease contributions to opam repositories
pkgs.opam-installer
Handle (un)installation from opam install files
pkgs.ocamlPackages.opam-core
Small standard library extensions, and generic system interaction modules used by opam
pkgs.ocamlPackages.opam-state
OPAM development library handling the ~/.opam hierarchy, repository and switch states
pkgs.ocamlPackages.opam-client
Actions on the opam root, switches, installations, and front-end
pkgs.ocamlPackages.opam-format
Definition of opam datastructures and its file interface
pkgs.ocamlPackages.opam-solver
This library is based on the Cudf and Dose libraries, and handles calls to the external solver from opam
pkgs.ocamlPackages.opam-repository
OPAM repository and remote sources handling, including curl/wget, rsync, git, mercurial, darcs backends
pkgs.ocamlPackages.opam-file-format
Parser and printer for the opam file syntax
pkgs.ocamlPackages_latest.opam-core
Small standard library extensions, and generic system interaction modules used by opam
pkgs.ocamlPackages_latest.opam-state
OPAM development library handling the ~/.opam hierarchy, repository and switch states
pkgs.ocamlPackages.opam-0install-cudf
Opam solver using 0install backend using the CUDF interface
-
nixos-unstable 0install-cudf-0.5.0
- nixpkgs-unstable 0install-cudf-0.5.0
- nixos-unstable-small 0install-cudf-0.5.0
-
nixos-25.11 0install-cudf-0.5.0
- nixos-25.11-small 0install-cudf-0.5.0
- nixpkgs-25.11-darwin 0install-cudf-0.5.0
pkgs.ocamlPackages_latest.opam-client
Actions on the opam root, switches, installations, and front-end
pkgs.ocamlPackages_latest.opam-format
Definition of opam datastructures and its file interface
pkgs.ocamlPackages_latest.opam-solver
This library is based on the Cudf and Dose libraries, and handles calls to the external solver from opam
pkgs.ocamlPackages_latest.opam-repository
OPAM repository and remote sources handling, including curl/wget, rsync, git, mercurial, darcs backends
pkgs.ocamlPackages_latest.opam-file-format
Parser and printer for the opam file syntax
pkgs.tree-sitter-grammars.tree-sitter-opam
Tree-sitter grammar for opam
-
nixos-unstable 0-unstable-2026-04-05
- nixpkgs-unstable 0-unstable-2026-04-05
- nixos-unstable-small 0-unstable-2026-04-05
pkgs.ocamlPackages_latest.opam-0install-cudf
Opam solver using 0install backend using the CUDF interface
-
nixos-unstable 0install-cudf-0.5.0
- nixpkgs-unstable 0install-cudf-0.5.0
- nixos-unstable-small 0install-cudf-0.5.0
pkgs.python313Packages.tree-sitter-grammars.tree-sitter-opam
Python bindings for tree-sitter-opam
-
nixos-unstable 0+unstable20260405
- nixpkgs-unstable 0+unstable20260405
- nixos-unstable-small 0+unstable20260405
pkgs.python314Packages.tree-sitter-grammars.tree-sitter-opam
Python bindings for tree-sitter-opam
-
nixos-unstable 0+unstable20260405
- nixpkgs-unstable 0+unstable20260405
- nixos-unstable-small 0+unstable20260405