CVE-2026-44641

Microsoft APM is an open-source, community-driven dependency manager for AI agents. Prior to 0.8.12, Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json into .apm/. The manifest fields agents, skills, commands, and hooks are attacker-controlled, but the implementation does not enforce that those paths remain inside the plugin directory. A malicious plugin can therefore use absolute paths or ../ traversal paths to copy arbitrary readable host files or directories from the installer's machine during apm install. This vulnerability is fixed in 0.8.12.
Configurations

No configuration.

History

15 May 2026, 19:17

Type Values Removed Values Added
References () https://github.com/microsoft/apm/security/advisories/GHSA-xhrw-5qxx-jpwr - () https://github.com/microsoft/apm/security/advisories/GHSA-xhrw-5qxx-jpwr -

15 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-15 17:16

Updated : 2026-05-18 19:33


NVD link : CVE-2026-44641

Mitre link : CVE-2026-44641

CVE.ORG link : CVE-2026-44641


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-73

External Control of File Name or Path