MEDIUM5.5PyPI
GHSA-mq5j-pw29-jcv3· CVE-2026-46383, PYSEC-2026-2378Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Modified: 7/13/2026
package
pkg:pypi/apm-cli
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Modified: 7/13/2026
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
Modified: 7/13/2026
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Modified: 7/13/2026
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
Modified: 7/13/2026