Junglewise Threat Intelligence

CVE-2026-46383: Microsoft APM path traversal in archive extraction

CVE-2026-46383 · Severity: medium · CVSS 5.5 · Published 2026-05-15

Technologies: Microsoft Apm-Cli. Vendors: Microsoft, PyPI.

Executive brief

Microsoft APM, a dependency manager for AI agents, is vulnerable to a file-handling flaw on Windows systems. When a user attempts to install a specially crafted local archive file, the software may inadvertently overwrite or create files in arbitrary locations on the user's computer. This could allow an attacker to modify sensitive configuration files or system data if they can convince a user to run the install command on a malicious file.

Technical details

A path traversal vulnerability exists in Microsoft APM (apm-cli) prior to version 0.13.0 when running on Windows with Python 3.10 or 3.11. The vulnerability occurs in the `_looks_like_legacy_apm_bundle()` function within `src/apm_cli/bundle/local_bundle.py`. When the `apm install` command is used on a local `.tar.gz` file, the application probes the archive to determine if it is a legacy bundle by calling `tar.extractall()`. On affected Python versions, this call does not properly validate Windows absolute paths (e.g., `D:/...`), allowing an attacker to craft an archive that writes or overwrites files outside the intended extraction directory. This occurs during the classification phase, even if the bundle is ultimately rejected as invalid. The issue is fixed in version 0.13.0 by implementing proper path validation.

Affected products

  • Microsoft APM (apm-cli) < 0.13.0

Timeline

  • 2026-05-11: advisory: GitHub Security Advisory published
  • 2026-05-15: disclosed: NVD publication date

References

Related threats