Boundary Failure in Microsoft APM Archive Extraction for AI Agents
CVE-2026-46383

5.5MEDIUM

Key Information:

Vendor

Microsoft

Status
Vendor
CVE Published:
15 May 2026

What is CVE-2026-46383?

Microsoft APM, an open-source dependency manager for AI agents, has a boundary failure in its archive extraction process prior to version 0.13.0. When an unrecognized .tar.gz file is processed by the legacy-bundle probe in the apm install command, the tool fails to reject Windows absolute member names in the extracted tar files. This could allow for untrusted tar members to be extracted, posing a risk for systems running Python versions 3.10 and 3.11. This issue has been addressed in the version 0.13.0 update.

Affected Version(s)

apm < 0.13.0

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.