SQL Injection Vulnerability in SAP HDI Deploy Package
CVE-2026-40131
3.4LOW
Key Information:
- Vendor
SAP
- Vendor
- CVE Published:
- 12 May 2026
What is CVE-2026-40131?
A SQL injection vulnerability exists in the @sap/hdi-deploy package, where user input is used to dynamically construct SQL queries without appropriate parameterization or prepared statements. This could enable users with elevated privileges to modify SELECT statements, thereby compromising the confidentiality and availability of the application. No impact on data integrity has been reported. To mitigate this risk, it is essential to implement proper input validation and parameterized queries. Resources for understanding the vulnerability can be found through SAP security notes.
Affected Version(s)
SAP HANA Deployment Infrastructure (HDI) deploy library XS_HDI_DEPLOYER 1.00