All 3 CVE vulnerabilities found in apm, with AI-generated Chinese analysis, references, and POCs.
Vendor: microsoft
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-46383 | Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install` CWE-22 | 5.5 | Medium | 2026-05-15 |
| CVE-2026-45539 | Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree CWE-59 | 7.4 | High | 2026-05-15 |
| CVE-2026-44641 | Microsoft APM: plugin.json component paths escape plugin root and copy arbitrary host files during install CWE-22 | 7.1 | High | 2026-05-15 |
All 3 known CVE vulnerabilities affecting apm with full Chinese analysis, references, and POCs where available.