CVE-2026-45539 | Microsoft apm up to 0.12.x apm-cli Path.glob/Path.rglob link following (GHSA-q5pp-gvjg-h7v4 / EUVD-2026-30561)
A vulnerability classified as critical has been found in Microsoft apm up to 0.12.x. The impacted element is the function Path.glob/Path.rglob of the component apm-cli. This manipulation causes link following.
This vulnerability is registered as CVE-2026-45539. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.