VYPR
Medium severity5.8NVD Advisory· Published Mar 5, 2024· Updated Jun 17, 2026

CVE-2024-27931

CVE-2024-27931

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in Deno.makeTemp* APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems. A user may provide a prefix or suffix to a Deno.makeTemp* API containing path traversal characters. This is fixed in Deno 1.41.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
denocrates.io
< 1.41.11.41.1

Affected products

3
  • Denoland/Deno2 versions
    cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*range: <1.41.1
    • (no CPE)range: < 1.41.1
  • ghsa-coords
    Range: < 1.41.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.