Skip to main content

Releases for April 2026

On April 29, 2026, Aikido Security disclosed an active supply chain attack targeting SAP developers. Four SAP npm packages were compromised with credential-stealing malware — specifically @cap-js/sqlite, @cap-js/postgres, @cap-js/db-service, and mbt.

enosix applications and systems are not affected.​

enosix products are built on Salesforce, TypeScript, React, and LWC. We do not use SAP CAP or MTA Build tooling anywhere in our codebase. We confirmed this with a full scan of all repositories in our GitHub organization — none of the affected packages appear in any form, and no indicators of compromise were found in our code, CI pipelines, or internal npm registry.

If you have questions or concerns, please reach out to the enosix team.

For the full technical write-up of this attack, see the Aikido Security advisory.

[Feature]: This release introduces strict query parameter validation in the API Proxy to prevent query parameter injection into downstream SAP requests. The change addresses an issue where encoded characters (e.g., %26 for &) could be used to pass additional parameters.

Allows only below-listed query parameters, and any additional parameters passed on request are dropped

  • sap-client: Exactly 3 digits
  • sap-sessioncmd: Must be cancel
  • sap-language: Exactly 2 characters
  • link-function: Must be auth-payload
  • saml2: Must be disabled
  • tabs: Letters only
  • key: String or the literal $*$
  • expirationSeconds: Positive integer 1..2147483647
  • cid: Alphanumeric less than or equal to 10 characters

🚀 Introducing arnold™ — Now Available for a Pilot​

We’re excited to announce the first public release of arnold™, a powerful new way to access and interact with SAP using AI.

You can now pilot arnold™ through a limited trial in your own environment and experience a completely new way of working with SAP data using AI.

👉 Ready to get started? Reach out to enosix to enable your pilot and see arnold™ in action: https://go.enosix.com/support

🤖 What is arnold™?​

arnold™ is an MCP Server (Model Context Protocol) that connects AI agents to SAP, allowing users to interact with SAP data using simple, natural language. Instead of navigating complex SAP screens or using transaction codes, users can simply ask questions—and take action—directly from chat.

With arnold™, you can:

  • 🔍 Retrieve real-time SAP data
  • ✏️ Update existing records
  • ➕ Create new transactions

No SAP GUI. No transaction codes. No delays.

🧠 How It Works (Simple View)​

  • Users interact with Agent through AI platforms like Microsoft 365 (Copilot)
  • AI agents translate the request to tools
  • arnold™ provides the right tools to interact with SAP
  • enosix SAP Platform responds in real time
  • Agent presents data to users in easily readable format

☁️ Built for Enterprise — Secure by Design​

arnold™ is:

  • Hosted in Microsoft Azure
  • Secured through Microsoft Entra Directory / M365
  • Supports Single Sign-On (SSO) and SAP Principal Propagation

Your SAP data remains secure while becoming more accessible than ever.

Enhancements​

  • Override CID on Link API requests. Support has been added to specify a Customizing ID on proxied API requests. Specifying a cid query string parameter will override the x-enosix-cid extension of the Open API Specification for the endpoint.

Bug Fixes​

  • Reading CID from Open API Specification. A bug causing API endpoints to ignore the configured x-enosix-cid extension in the Open API Specification.

Enhancements​

Ability to pass CID as Query Param.

Added support for passing cid as a query parameter to the SAP backend. The following validation rules have been added for the cid parameter:

  • Alphanumeric characters only (a-z, A-Z, 0-9)
  • Length: 1-10 characters
  • No special characters or spaces allowed