APM – Agent Package Manager是Microsoft开源的一款AI代理依赖管理工具。 APM – Agent Package Manager 0.13.0之前版本存在路径遍历漏洞,该漏洞源于Windows特定的归档提取边界失败,在Python 3.10和3.11运行时上使用apm install时,对本地.tar.gz文件进行遗留格式探测时使用raw tar.extractall提取不受信任的tar成员,未拒绝Windows绝对成员名,可能导致任意文件写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-45539 | 7.4 HIGH | Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during ` |
| CVE-2026-44641 | 7.1 HIGH | Microsoft APM: plugin.json component paths escape plugin root and copy arbitrary host file |
No comments yet