Vulnerability Description
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/[email protected]`, `@cap-js/[email protected]`, and `@cap-js/[email protected]` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.
Related Weaknesses (CWE)
References
- https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8
- https://me.sap.com/notes/3747787
- https://www.sap.com/documents/2026/05/8203a8b9-4d7f-0010-bca6-c68f7e60039b.html
- https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared
FAQ
What is CVE-2026-46421?
CVE-2026-46421 is a documented vulnerability. The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, c...
How severe is CVE-2026-46421?
CVSS scoring is not yet available for CVE-2026-46421. Check NVD for updates.
Is there a patch for CVE-2026-46421?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.