CVE-2021-32619: Static imports inside dynamically imported modules do not adhere to permission checks
Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through import() or new Worker might have been able to bypass network and file system permission checks when statically importing other modules. The vulnerability has been patched in Deno release 1.10.2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32619?
CVE-2021-32619 is a vulnerability in Deno, a runtime for JavaScript and TypeScript, which allows bypassing network and file system permission checks when dynamically importing modules.
What is the severity of CVE-2021-32619?
The severity of CVE-2021-32619 is critical with a CVSS score of 9.8.
Which software versions are affected by CVE-2021-32619?
Deno versions 1.5.0 to 1.10.1 are affected by CVE-2021-32619.
How can I mitigate the CVE-2021-32619 vulnerability?
To mitigate the vulnerability, it is recommended to update Deno to version 1.10.2 or later.
Where can I find more information about CVE-2021-32619?
More information about CVE-2021-32619 can be found in the Deno Security Advisory at: https://github.com/denoland/deno/security/advisories/GHSA-xpwj-7v8q-mcgj