Executive brief
Deno is a software runtime used to execute JavaScript and TypeScript applications. A security flaw in its permission system allows an application to modify environment variables even when specifically restricted from doing so. If an attacker can control a configuration file on the system, they could bypass security boundaries to inject unauthorized settings into the running program.
Technical details
An authorization bypass exists in Deno's Node-compatible 'process.loadEnvFile()' API. While Deno normally gates environment access via the '--allow-env' or '--deny-env' flags, this specific function only validates file read permissions ('--allow-read') before writing keys from a .env file into 'process.env'. A local attacker or malicious dependency that can control a .env file can effectively bypass environment restrictions to mutate the process environment. This issue affects Deno versions 2.3.0 through 2.8.0 and is resolved in version 2.8.1.
Affected products
- denoland Deno >= 2.3.0, < 2.8.1
Timeline
- 2026-05-27: advisory: GitHub advisory published by denoland
- 2026-06-23: disclosed: CVE published to NVD
- 2026-06-23: patched: Fix released in version 2.8.1