Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
Vulnerability Description
The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL database services for that tool. On April 29, 2026, compromised versions of `@cap-js/sqlite@2.2.2`, `@cap-js/postgres@2.2.2`, and `@cap-js/db-service@2.10.1` were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised. User should upgrade to `@cap-js/sqlite` >= 2.4.0, `@cap-js/postgres` >= 2.3.0, `@cap-js/db-service` >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials. No known workarounds are available.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Type
内嵌的恶意代码
Vulnerability Title
SAP Cloud Application Programming Model @cap-js/db-service 处理逻辑错误漏洞
Vulnerability Description
SAP Cloud Application Programming Model @cap-js/db-service是SAP Cloud Application Programming Model公司的一个基础数据库服务,为所有支持的数据库提供统一的核心架构层。 SAP Cloud Application Programming Model @cap-js/db-service存在处理逻辑错误漏洞,该漏洞源于恶意软件包植入,可能导致凭据被窃取和传播。以下产品及版本受到影响:@cap-js/sqlite 2
CVSS Information
N/A
Vulnerability Type
N/A