apm-cli vulnerabilities
CVEs whose affected-version data names the apm-cli package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-46383Medium· 5.5Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
▾ Sunlitapm-cli · apm-cliEPSS 0.61%via OSV
CVE-2026-44641High· 7.1Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
▾ Twilightapm-cli · apm-cliEPSS 0.32%via OSV