SAP Knowledge Base Article - Preview

3785740 - security scan reports high-severity pacote issue in sapui5 mcp server (@ui5/mcp-server)

Symptom

A high-severity vulnerability (SNYK-JS-PACOTE-8225084) has been reported in the pacote package, which appears as a dependency of @ui5/mcp-server (UI5 MCP Server).
As shown in the npm dependency graph of the latest release (v0.2.14), pacote version 19.0.2 is included in the dependency tree.

You would like to understand whether this vulnerability has any impact on @ui5/mcp-server and its usage.




Read more...

Product

SAP S/4HANA all versions

Keywords

@ui5/mcp-server, sapui5 mcp server, pacote, snyk-js-pacote-8225084, addGitSha, git spec, registry spec, ui5 project, ui5 tooling, vulnerability scan, transitive dependency, false positive, npm audit, high severity, node.js compatibility , KBA , CA-UI5-COR-FND , Foundation team , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.