Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mq5j-pw29-jcv3 | Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install` |
Fri, 15 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 15 May 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is given a local .tar.gz that is not recognized as a plugin-format bundle, APM probes whether it is a legacy --format apm bundle. On Python versions earlier than 3.12, that probe extracts untrusted tar members with raw tar.extractall() without rejecting Windows absolute member names such as D:/.... This vulnerability is fixed in 0.13.0. | |
| Title | Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install` | |
| Weaknesses | CWE-22 CWE-73 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-15T17:49:11.229Z
Reserved: 2026-05-13T19:53:47.922Z
Link: CVE-2026-46383
Updated: 2026-05-15T17:48:01.747Z
Status : Received
Published: 2026-05-15T17:16:49.090
Modified: 2026-05-15T19:17:04.220
Link: CVE-2026-46383
No data.
OpenCVE Enrichment
Updated: 2026-05-15T17:30:04Z
Github GHSA