UI5 Web Components: webcomponents.base
84%
Total Score
healthy
Healthy, with workflow permission and script-injection concerns that warrant review before relying on releases.
All 14 workflows were analyzed, but the audit found one script-injection issue, broad app-token permissions, and 49 of 56 action references unpinned. These are meaningful release-automation hygiene concerns, though no untrusted checkout or dangerous trigger was reported.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-760121 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @ui5/webcomponents-base is vulnerable to Origin Validation Error in versions 1.12.0 - 2.21.1. | 1.12.0 - 2.21.1 | Low |
AIKIDO-2026-707978 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @ui5/webcomponents-base is vulnerable to Inclusion of Functionality from Untrusted Control Sphere in versions 1.12.0 - 2.17.1. | 1.12.0 - 2.17.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
lit-html Version ^2.0.1 | — | — |
@lit-labs/ssr-dom-shim Version ^1.1.2 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.