VYPR

@sap/hdi Deploy

by SAP

CVEs (1)

  • CVE-2026-40131LowMay 12, 2026
    risk 0.22cvss 3.4epss 0.00

    SQL injection vulnerability exists in @sap/hdi-deploy package, where SQL queries are dynamically constructed using user input without proper parameterization or prepared statements. Successful exploitation could allow the high privileged users to alter the SELECT statements…