
By the grace of God, my Microsoft APM research led to CVE-2026-45539 / EUVD-2026-30561. A malicious package could use a symlink to escape the package root and read local host files during "apm install". Affected: 0.5.2–0.12.4 Fixed: 0.13.0 @msftsecresponse #Microsoft #Cyber https://t.co/A5PFX8Nvr3
Post summary
The tweet announces CVE‑2026‑45539, detailing a symlink-based root escape in Microsoft APM, and notes that versions 0.13.0 and later contain the fix.


