Description
Affected versions of @sap-cloud-sdk/core do not properly validate JWTs. The verifyJwt() function does not properly validate the URL from where the public verification key for the JWT can be downloaded. Any URL was trusted which makes it possible to provide a URL belonging to a manipulated JWT.
Recommendation
Update the @sap-cloud-sdk/core package to the latest compatible version. Followings are version details:
- Affected version(s): >= 1.19.0, < 1.21.2
- Patched version(s): 1.21.2
References
Could your website be exposed too?
SmartScanner can check your website for Improper Authorization in @sap-cloud-sdk/core and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Unauthorized access to data in @sap-cloud-sdk/core - CVE-2021-41251
- Improper Verification of Cryptographic Signature in aws-encryption-sdk-javascript - Vulnerability
- MCPHub has an Improper Authorization vulnerability via its handleSseConnection function - CVE-2025-11287
- Improper Authorization in react-oauth-flow - Vulnerability


