Junglewise Threat Intelligence

CVE-2026-49983: Deno environment permission bypass in process.loadEnvFile

CVE-2026-49983 · Severity: medium · CVSS 5.2 · Published 2026-06-23

Technologies: Denoland Deno. Vendors: crates.io.

Executive brief

Deno is a software runtime used to execute JavaScript and TypeScript applications. A security flaw in its permission system allows an application to modify environment variables even when specifically restricted from doing so. If an attacker can control a configuration file on the system, they could bypass security boundaries to inject unauthorized settings into the running program.

Technical details

An authorization bypass exists in Deno's Node-compatible 'process.loadEnvFile()' API. While Deno normally gates environment access via the '--allow-env' or '--deny-env' flags, this specific function only validates file read permissions ('--allow-read') before writing keys from a .env file into 'process.env'. A local attacker or malicious dependency that can control a .env file can effectively bypass environment restrictions to mutate the process environment. This issue affects Deno versions 2.3.0 through 2.8.0 and is resolved in version 2.8.1.

Affected products

  • denoland Deno >= 2.3.0, < 2.8.1

Timeline

  • 2026-05-27: advisory: GitHub advisory published by denoland
  • 2026-06-23: disclosed: CVE published to NVD
  • 2026-06-23: patched: Fix released in version 2.8.1

References

Related threats