Description
The SAP Approuter Node.js package version v16.7.1 and before is vulnerable to Authentication bypass. When trading an authorization code, an attacker can steal the session of the victim by injecting malicious payload, causing High impact on confidentiality and integrity of the application.
Recommendation
Update the @sap/approuter package to the latest compatible version. Followings are version details:
- Affected version(s): >= 2.6.1, < 16.7.2
- Patched version(s): 16.7.2
References
- GHSA-cpfx-964w-4jvp
- me.sap.com
- www.npmjs.com
- support.sap.com
- CVE-2025-24876
- CWE-601
- CAPEC-310
- OWASP 2021-A1
- OWASP 2021-A6
Related Issues
- MCPHub has an authentication bypass - CVE-2025-13822
- FUXA has JWT Authentication Bypass via HTTP Referer header spoofing - CVE-2025-69985
- Authentication Bypass via Default JWT Secret in NocoBase docker-compose Deployments - CVE-2025-13877
- Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage - CVE-2025-63700
You might also like:
- Tags:
- npm
- @sap/approuter
Anything's wrong? Let us know Last updated on February 11, 2025


