CVE-2026-46421 Details
Description
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/[email protected]`, `@cap-js/[email protected]`, and `@cap-js/[email protected]` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.
A supply chain attack has been identified in the SAP Cloud Application Programming Model, specifically within the cap-js/cds-dbs monorepo for SQL database services. On April 29, 2026, malicious versions of the packages @cap-js/[email protected], @cap-js/[email protected], and @cap-js/[email protected] were published. These compromised packages included a preinstall hook that downloaded the Bun JavaScript runtime and executed an obfuscated payload designed to harvest credentials and propagate the infection. As a result, all credentials accessible on the machine where the compromised version was installed, including npm tokens, cloud provider credentials, SSH keys, and GitHub Personal Access Tokens, should be considered compromised.
Users should uninstall the compromised package versions and upgrade to the latest safe versions. For @cap-js/sqlite, the safe version is 2.4.0 or higher; for @cap-js/postgres, it is 2.3.0 or higher; and for @cap-js/db-service, it is 2.11.0 or higher. After upgrading, all affected credentials should be rotated.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 15, 2026CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/cap-js/cds-dbs/security/advisories/GHSA-pvw4-cvr4-97p8 | [email protected] | AdvisoryRemedy |
| https://me.sap.com/notes/3747787 | [email protected] | Permission RequiredVendor |
| https://www.sap.com/documents/2026/05/8203a8b9-4d7f-0010-bca6-c68f7e60039b.html | [email protected] | |
| https://www.stepsecurity.io/blog/a-mini-shai-hulud-has-appeared | [email protected] | BundleExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SAP Cloud Application Programming Model | All versions |
CPE
Remediation
| |
| SAP cap-js/sqlite | 2.2.2 (semver) |
CPE
Remediation
| |
| SAP cap-js/postgres | 2.2.2 (semver) |
CPE
Remediation
| |
| SAP cap-js/db-service | 2.10.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |
Volerion