CVE-2026-45539Disclosure

LOWCVSS 7.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rglob() calls and read each match with Path.read_text(), transparently following symbolic links. A symlink committed inside a remote APM dependency under .apm/prompts/<x>.prompt.md or .apm/agents/<x>.agent.md is preserved verbatim into apm_modules/ on clone and then dereferenced during integration, with the resolved content written as a regular file into the project's deploy directories. The package content_hash, the pre-deploy SecurityGate scan, and apm audit do not flag this. The deploy roots are not added to the auto-generated .gitignore, so the resulting files are staged by git add by default. This vulnerability is fixed in 0.13.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-59CWE-200

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-16); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-16: 1Mentions · 2026-05-30: 1Mentions · 2026-08-21: 1PoC Mentioned / Linked · 2026-05-16: 1Patch / Workaround · 2026-08-21: 1Technical Details · 2026-05-16: 1Technical Details · 2026-08-21: 105-1605-3008-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
Full discourse3 posts
  • Ali shmery@Alishmery2
    Disclosure

    By the grace of God, my Microsoft APM research led to CVE-2026-45539 / EUVD-2026-30561. A malicious package could use a symlink to escape the package root and read local host files during "apm install". Affected: 0.5.2–0.12.4 Fixed: 0.13.0 @msftsecresponse #Microsoft #Cyber https://t.co/A5PFX8Nvr3

    Post summary

    The tweet announces CVE‑2026‑45539, detailing a symlink-based root escape in Microsoft APM, and notes that versions 0.13.0 and later contain the fix.

    00030112
    16 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    【脆弱性情報】 CVE-2026-45539 Microsoft APM 0.5.4 から 0.12.4の脆弱性について https://www.cybernote.click/2026/05/29/%e3%80%90%e8%84%86%e5%bc%b1%e6%80%a7%e6%83%85%e5%a0%b1%e3%80%91-cve-2026-45539-microsoft-apm-0-5-4-%e3%81%8b%e3%82%89-0-12-4%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%81%ab%e3%81%a4%e3%81%84%e3%81%a6/ #IT #Security #cybersecurity

    Post summary

    A brief notice of CVE-2026-45539 affecting Microsoft APM versions 0.5.4 to 0.12.4, with only the CVE identifier, affected product, and a link to an article.

    0000049
    209 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2026-45539 | Microsoft apm up to 0.12.x apm-cli Path.glob/Path.rglob link following (GHSA-q5pp-gvjg-h7v4) https://ift.tt/ajloQgR A vulnerability classified as critical has been found in Microsoft apm up to 0.12.x. The impacted element is the function Path.glob/Path.rglob o…

    Post summary

    The text announces a critical CVE‑2026‑45539 affecting Microsoft apm 0.12.x, highlighting the vulnerable Path.glob/Path.rglob function and linking to further details via GHSA, without mention of exploits, patches, or active attacks.

    0000047
    974 followersView on X

Explore more