apm-cli has 2 CVEs on record. The median CVSS is 6.3 (medium).
CVEs per month
Last 12 months, by publish date
1025/101125/111225/120126/010226/020326/030426/040526/050626/060726/070826/080926/09
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 2
Products
- apm-cli 2
2
Total CVEs
0
Critical
0
CISA KEV
0
Exploited
apm-cli vulnerabilities
CVEs affecting apm-cli, newest first. Open any entry for full detail, references, and exploit status.
2 CVEsRSS
CVE-2026-46383Medium· 5.5Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`
▾ Sunlitapm-cli · apm-cliEPSS 0.61%via OSV
CVE-2026-44641High· 7.1Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
▾ Twilightapm-cli · apm-cliEPSS 0.32%via OSV