CVE-2021-41641

HIGH8.4EPSS 0.13%

Link Following in Deno

Published: 6/13/2022Modified: 11/8/2023
Also known as:GHSA-67hm-27mx-9cg7

Description

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH8.4CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N

References (5)