Tag
high
advisory
APM CLI Symlink Vulnerability Leads to File Content Disclosure (CVE-2026-45539)
2 rules 1 TTP 1 CVEA vulnerability in the `apm-cli` tool allows a malicious APM package to include symlinks that, when installed, can lead to file-content disclosure, by dereferencing symlinks under `.apm/prompts/` and `.apm/agents/` during `apm install`, and copying host-local file contents into the project tree.
apm
symlink
file-disclosure
apm-cli
dependency-confusion
2r
1t
1c
high
advisory
Microsoft APM CLI Path Traversal Vulnerability
2 rules 1 TTPMicrosoft APM CLI version 0.8.11 and earlier are vulnerable to path traversal, allowing a malicious plugin to copy arbitrary readable host files during installation by manipulating paths in the plugin.json file.
apm-cli
path-traversal
supply-chain
2r
1t