VDB
Sign up
CRITICAL10.0

GHSA-838h-jqp6-cf2f

Sandbox bypass leading to arbitrary code execution in Deno

Details

### Impact

The versions of Deno between release 1.18.0 and 1.20.2 (inclusive) are vulnerable to an attack where a malicious actor controlling the code executed in a Deno runtime could bypass permission checks and execute arbitrary shell code.

There is **no** evidence that this vulnerability has been exploited in the wild.

This vulnerability does **not** affect users of Deno Deploy.

### Patches

The vulnerability has been patched in Deno 1.20.3.

### Workarounds

There is no workaround. All users are recommended to upgrade to 1.20.3 immediately

---

The cause of this error was that certain FFI operations did not correctly check for permissions. The issue was fixed in [this](https://github.com/denoland/deno/pull/14115) pull request.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/deno
Introduced in: 1.18.0Fixed in: 1.20.3

Upgrade deno to 1.20.3 or newer (ecosystem crates.io).

References