CVE-2026-46421Disclosure

LOWCVSS 9.3 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/[email protected]`, `@cap-js/[email protected]`, and `@cap-js/[email protected]` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-21); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-21: 1Mentions · 2026-07-07: 1Active Exploitation · 2026-07-07: 1Technical Details · 2026-07-07: 105-2107-07
Signal classification2 categories
Disclosure
150.0%
Active Exploitation
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-05-211
Disclosure1
2026-07-071
Active Exploitation1
Full discourse2 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    Update: a CVE has now been assigned for the Mini Shai-Hulud compromise of the cap-js npm packages - CVE-2026-46421. Full details: https://github.com/advisories/GHSA-pvw4-cvr4-97p8

    Post summary

    The text announces the assignment of CVE‑2026‑46421 to the cap‑js packages, citing a GitHub advisory for full details.

    0002075
    196 followersView on X
  • Jacek Bugajski@DzejBi_JB
    Active Exploitation

    4/ Napastnik potrzebuje otwartych drzwi. SAP je dostarczył. Ostatni cykl not: - CVE-2026-44748 (9.9): obejście SAML w NetWeaver ABAP - CVE-2026-27671 (9.8): memory corruption w RFC, BEZ workaroundu Plus supply-chain z maja: złośliwe pakiety npm w CAP na BTP (CVE-2026-46421)

    Post summary

    The post announces severe CVEs, notes a lack of workarounds, and reports malicious npm packages in a supply‑chain context, indicating active exploitation in the wild.

    1000077
    338 followersView on X

Explore more