GHSA-pvw4-cvr4-97p8

Suggest an improvement
Source
https://github.com/advisories/GHSA-pvw4-cvr4-97p8
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pvw4-cvr4-97p8/GHSA-pvw4-cvr4-97p8.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-pvw4-cvr4-97p8
Aliases
  • CVE-2026-46421
Published
2026-05-20T15:33:04Z
Modified
2026-09-10T03:51:06Z
Summary
Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
Details

Impact

On April 29, 2026, compromised versions of @cap-js/sqlite@2.2.2, @cap-js/postgres@2.2.2, and @cap-js/db-service@2.10.1 were published. The malicious packages harvested credentials and attempted self-propagation. If a compromised version was installed, all credentials accessible on that machine (npm tokens, cloud provider credentials, SSH keys, GitHub PATs) should be considered compromised.

Patches

Upgrade to @cap-js/sqlite >= 2.4.0, @cap-js/postgres >= 2.3.0, @cap-js/db-service >= 2.11.0. If a compromised version was ever installed, rotate all affected credentials.

Workarounds

No workarounds.

Database specific
{
    "cwe_ids":  [
        "CWE-506"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-20T15:33:04Z",
    "nvd_published_at":  null,
    "severity":  "CRITICAL"
}
References

Affected packages

npm / @cap-js/sqlite

Package

Name
@cap-js/sqlite
View open source insights on deps.dev
Purl
pkg:npm/%40cap-js/sqlite

Affected ranges

Type
SEMVER
Events
Introduced
2.2.2
Fixed
2.3.0

Affected versions

2.*
2.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pvw4-cvr4-97p8/GHSA-pvw4-cvr4-97p8.json"

npm / @cap-js/postgres

Package

Name
@cap-js/postgres
View open source insights on deps.dev
Purl
pkg:npm/%40cap-js/postgres

Affected ranges

Type
SEMVER
Events
Introduced
2.2.2
Fixed
2.3.0

Affected versions

2.*
2.2.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pvw4-cvr4-97p8/GHSA-pvw4-cvr4-97p8.json"

npm / @cap-js/db-service

Package

Name
@cap-js/db-service
View open source insights on deps.dev
Purl
pkg:npm/%40cap-js/db-service

Affected ranges

Type
SEMVER
Events
Introduced
2.10.1
Fixed
2.11.0

Affected versions

2.*
2.10.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-pvw4-cvr4-97p8/GHSA-pvw4-cvr4-97p8.json"