sapui5-cli
Warn
Audited by Socket on Sep 15, 2026
1 alert found:
AnomalyAnomalytemplates/custom-middleware-template.js
LOWAnomalyLOW
templates/custom-middleware-template.js
No evidence of intentional malware, data exfiltration, backdoors, or sabotage is present. The code appears to be a collection of example middleware implementations. Security concerns include potential stored XSS from unsanitized Markdown, possible cross-user response leakage from the global URL-only cache, configuration-dependent SSRF through the proxy, unrestricted upload resource consumption, permissive CORS, and reliance on the resource resolver for path safety. These issues warrant review before production use.
Confidence: 96%Severity: 62%
Audit Metadata