CVE-2026-49406
published 2026-06-23CVE-2026-49406: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did…
PriorityP429medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.18%
7.3th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved entrypoint stayed within its node_modules// directory. A malicious package.json whose main field contained .. segments was able to resolve to an arbitrary path on disk, and the resolver then read that file without consulting the --allow-read allowlist. This let a require("evil-pkg") call return the contents of a file that a direct Deno.readTextFileSync(...) call would have been blocked from reading. This vulnerability is fixed in 2.7.12.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | < 2.7.12 | 2.7.12 |
| deno | deno | >= 0 < 2.7.12 | 2.7.12 |
| denoland | deno | < 2.7.12 | 2.7.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.7.11 Resolver package.json path traversal (GHSA-968w-xfqw-vp9q)
vuldb·2026-06-23·CVSS 5.5
CVE-2026-49406 [MEDIUM] denoland deno up to 2.7.11 Resolver package.json path traversal (GHSA-968w-xfqw-vp9q)
A vulnerability has been found in denoland deno up to 2.7.11 and classified as critical. The affected element is an unknown function of the file package.json of the component Resolver. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-49406. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.
GHSA
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
ghsa·2026-06-16
CVE-2026-49406 [MEDIUM] CWE-22 Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions
## Summary
When Deno was run in BYONM mode (`nodeModulesDir: "manual"`), the module resolver did not validate that a package's resolved entrypoint stayed within its `node_modules//` directory. A malicious `package.json` whose `main` field contained `..` segments was able to resolve to an arbitrary path on disk, and the resolver then read that file without consulting the `--allow-read` allowlist. This let a `require("evil-pkg")` call return the contents of a file that a direct `Deno.readTextFileSync(...)` call would have been blocked from reading.
## Details
In BYONM mode, Deno resolved npm packages directly from a user-managed `node_modules` tree. Resolution of `require("pkg")`
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published