0.19.0
9 months ago
1 days ago
Known vulnerabilities in the apm-cli package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
apm-cli is a MCP configuration tool Affected versions of this package are vulnerable to External Control of File Name or Path through the Note: This is only exploitable if the victim is running on Windows with Python 3.10 or 3.11 and executes the install command on a maliciously crafted local bundle. How to fix External Control of File Name or Path? Upgrade | [,0.13.0) |
apm-cli is a MCP configuration tool Affected versions of this package are vulnerable to Symlink Attack during the integration when symbolic links under certain directories are dereferenced and their target file contents are copied into project deployment directories. An attacker can access sensitive files from the host system by crafting a malicious package that includes symlinks pointing to arbitrary files, which are then read and written into the project during installation. How to fix Symlink Attack? Upgrade | [0.5.4,0.13.0) |
apm-cli is a MCP configuration tool Affected versions of this package are vulnerable to External Control of File Name or Path through improper validation of manifest-controlled paths in the How to fix External Control of File Name or Path? Upgrade | [,0.8.12) |