npm package report

Is @sap-cloud-sdk/core safe?

2 known vulnerabilities, worst severity HIGH.

cvss
7.5

how bad it is if exploited, out of 10

epss
not scored

chance of exploitation in the next 30 days

xyz score
3.3

CyberXYZ composite, out of 10

fig. 01 — GHSA-r2vw-jgq9-jqx2, the advisory selected below

// advisories

GHSA-r2vw-jgq9-jqx2

HIGH

Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.

Affected
>= 1.19.0, < 1.21.2, >=1.19.0, <1.21.2
Fixed in
1.21.2
Weakness
CWE-285
Published
2020-09-03
Source
github

GHSAreference


// ai model usage

Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


Checked 2026-09-22 at 01:40 UTC. The most recent advisory here was published 2021-11-10. Updated continuously from NVD, GHSA, OSV and CNA feeds.

Think a verdict here is wrong? Tell us — we respond within 2 business days.
Is @sap-cloud-sdk/core safe? npm package security report | CyberXYZ