Symptom
A high-severity vulnerability (SNYK-JS-PACOTE-8225084) has been reported in the pacote package, which appears as a dependency of @ui5/mcp-server (UI5 MCP Server).
As shown in the npm dependency graph of the latest release (v0.2.14), pacote version 19.0.2 is included in the dependency tree.
You would like to understand whether this vulnerability has any impact on @ui5/mcp-server and its usage.
Read more...
Product
Keywords
@ui5/mcp-server, sapui5 mcp server, pacote, snyk-js-pacote-8225084, addGitSha, git spec, registry spec, ui5 project, ui5 tooling, vulnerability scan, transitive dependency, false positive, npm audit, high severity, node.js compatibility , KBA , CA-UI5-COR-FND , Foundation team , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview