VYPR
Medium severity5.5GHSA Advisory· Published Jun 23, 2026· Updated Jun 26, 2026

CVE-2026-49406

CVE-2026-49406

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved entrypoint stayed within its node_modules// directory. A malicious package.json whose main field contained .. segments was able to resolve to an arbitrary path on disk, and the resolver then read that file without consulting the --allow-read allowlist. This let a require("evil-pkg") call return the contents of a file that a direct Deno.readTextFileSync(...) call would have been blocked from reading. This vulnerability is fixed in 2.7.12.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
denocrates.io
< 2.7.122.7.12

Affected products

2
  • Denoland/Deno2 versions
    cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*range: <2.7.12
    • (no CPE)range: <= 2.7.11

Patches

Vulnerability mechanics

References

3

News mentions

1