📡 GitHub-Advisory · 2026-05-07
CVE-2026-44641 - Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbi
CVE-2026-44641
GHSA-xhrw-5qxx-jpwr HIGH pip/apm-cli
CVE: CVE-2026-44641
Summary
Microsoft APM normalizes marketplace plugins by copying plugin components referenced in plugin.json into .apm/. The manifest fields agents, skills, commands, and hooks