{"id":"CVE-2026-46383","aliases":["GHSA-mq5j-pw29-jcv3","PYSEC-2026-2378"],"url":"https://o3.security/vulnerability/CVE-2026-46383","summary":"Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`","details":"Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.13.0, Microsoft APM contains a Windows-specific archive extraction boundary failure in the legacy-bundle probe used by apm install <bundle> on supported Python 3.10 and 3.11 runtimes. When apm install is given a local .tar.gz that is not recognized as a plugin-format bundle, APM probes whether it is a legacy --format apm bundle. On Python versions earlier than 3.12, that probe extracts untrusted tar members with raw tar.extractall() without rejecting Windows absolute member names such as D:/.... This vulnerability is fixed in 0.13.0.","published":"2026-05-15T16:04:24.050Z","modified":"2026-08-12T03:51:31.750582521Z","cvss":{"score":5.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N"},"epss":{"score":0.0061,"percentile":0.46078,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"apm-cli","fixedVersion":"0.13.0"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/46xxx/CVE-2026-46383.json"},{"type":"ADVISORY","url":"https://github.com/microsoft/apm/security/advisories/GHSA-mq5j-pw29-jcv3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46383"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.750582521Z"}}