-
Notifications
You must be signed in to change notification settings - Fork 5.7k
Security: denoland/deno
Security Navigation
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Command Injection on WindowsGHSA-m2gf-x3f6-8hq3 published
Oct 7, 2025 by bartlomiejuHigh -
Deno.FsFile.prototype.utime and Deno.FsFile.prototype.utimeSync --deny-write permission bypassGHSA-vg2r-rmgp-cgqj published
Oct 7, 2025 by bartlomiejuLow -
Deno.FsFile.prototype.stat and Deno.FsFile.prototype.statSyn --deny-read permission bypassGHSA-qq26-84mh-26j9 published
Oct 7, 2025 by bartlomiejuLow -
deno run with --allow-read and --deny-read flags results in allowedGHSA-xqxc-x6p3-w683 published
Jun 3, 2025 by bartlomiejuLow -
Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variablesGHSA-7w8p-chxq-2789 published
Jun 3, 2025 by bartlomiejuModerate -
--allow-read / --allow-write permission bypass in `node:sqlite`GHSA-8vxj-4cph-c596 published
Jun 3, 2025 by bartlomiejuHigh -
AES GCM authentication tags are not verifiedGHSA-2x3r-hwv5-p32x published
Jun 3, 2025 by bartlomiejuModerate -
fetch: Authorization headers not dropped when redirecting cross-originGHSA-f27p-cmv8-xhm6 published
Jan 6, 2025 by bartlomiejuHigh -
Private npm registry support used scope auth token for downloading tarballsGHSA-rfc6-h225-3vxv published
Jun 6, 2024 by bartlomiejuHigh -
Improper neutralization of input during web page generation ("Cross-site Scripting") in deno_doc HTML generatorGHSA-qqwr-j9mm-fhw6 published
Nov 25, 2024 by bartlomiejuModerate