CVE-2026-49983
published 2026-06-23CVE-2026-49983: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env…
PriorityP425medium5.2CVSS 3.1
AVLACLPRLUINSCCLILAN
EPSS
0.14%
3.7th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env permission cannot change process.env. process.loadEnvFile() (the Node-compatible API for loading variables from a .env file) does not honor this. It only checks that the program has read permission for the dotenv file, then writes every key in that file into the process environment — even when env access is denied. In effect, --allow-read plus a writable or attacker-controlled .env file is enough to defeat --deny-env. This vulnerability is fixed in 2.8.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | >= 0 < 2.8.1 | 2.8.1 |
| deno | deno | >= 2.3.0 < 2.8.1 | 2.8.1 |
| denoland | deno | < 2.8.1 | 2.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
denoland deno up to 2.8.0 Node-compatible API process.loadEnvFile authorization (GHSA-4c8g-jvcx-v4hv)
vuldb·2026-06-23·CVSS 5.2
CVE-2026-49983 [MEDIUM] denoland deno up to 2.8.0 Node-compatible API process.loadEnvFile authorization (GHSA-4c8g-jvcx-v4hv)
A vulnerability identified as problematic has been detected in denoland deno up to 2.8.0. Affected by this issue is the function process.loadEnvFile of the component Node-compatible API. Performing a manipulation results in incorrect authorization.
This vulnerability is identified as CVE-2026-49983. The attack is only possible with local access. There is not any exploit available.
You should upgrade the affected component.
GHSA
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
ghsa·2026-06-16
CVE-2026-49983 [MEDIUM] CWE-863 Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
## Summary
In Deno, environment access is gated by the `env` permission. You can deny it
with `--deny-env`, or restrict it to a specific allowlist with
`--allow-env=FOO,BAR`. The expectation is that a program running without `env`
permission cannot change `process.env`.
`process.loadEnvFile()` (the Node-compatible API for loading variables from a
`.env` file) does **not** honor this. It only checks that the program has
**read** permission for the dotenv file, then writes every key in that file
into the process environment — even when `env` access is denied.
In effect, **`--allow-read` plus a writable or attacker-controlled `.env` file
is enough to defeat `--deny-env`.**
## Am I aff
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-23
Published