CVE-2024-27931: Insufficient permission checking in `Deno.makeTemp*` APIs

Published Mar 5, 2024
·
Updated

Impact

Insufficient validation of parameters in Deno.makeTemp APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems.

A user may provide a prefix or suffix to a Deno.makeTemp API containing path traversal characters. The permission check would prompt for the base directory of the API, but the final file that was created would be outside of this directory:

$ mkdir /tmp/good $ mkdir /tmp/bad $ deno repl --allow-write=/tmp/good Deno.makeTempFileSync({ dir: "/tmp/bad" }) ┌ ⚠️ Deno requests write access to "/tmp/bad". ├ Requested by Deno.makeTempFile() API. ├ Run again with --allow-write to bypass this prompt. └ Allow? [y/n/A] (y = yes, allow; n = no, deny; A = allow all write permissions) > n ❌ Denied write access to "/tmp/bad". Uncaught PermissionDenied: Requires write access to "/tmp/bad", run again with the --allow-write flag at Object.makeTempFileSync (ext:denofs/30fs.js:176:10) at <anonymous>:1:27 Deno.makeTempFileSync({ dir: "/tmp/good", prefix: "../bad/" }) "/tmp/good/../bad/a9432ef5" $ ls -l /tmp/bad/a9432ef5 -rw-------@ 1 user group 0 Mar 4 09:20 /tmp/bad/a9432ef5

Patches

This is fixed in Deno 1.41.1.

Other sources

Deno is a JavaScript, TypeScript, and WebAssembly runtime with secure defaults. Insufficient validation of parameters in Deno.makeTemp APIs would allow for creation of files outside of the allowed directories. This may allow the user to overwrite important files on the system that may affect other systems. A user may provide a prefix or suffix to a Deno.makeTemp API containing path traversal characters. This is fixed in Deno 1.41.1.

— NVD

Affected Software

2 affected componentsFixes available
rust/deno<1.41.1
1.41.1
deno deno<1.41.1

Event History

Mar 5, 2024
Advisory Published
via GitHub·04:19 PM
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-27931?

CVE-2024-27931 is classified as a medium severity vulnerability due to insufficient validation of parameters.

2

How do I fix CVE-2024-27931?

To fix CVE-2024-27931, update Deno to version 1.41.1 or later.

3

What does CVE-2024-27931 affect?

CVE-2024-27931 affects the Deno runtime, specifically its makeTemp* APIs.

4

What are the potential impacts of CVE-2024-27931?

The impacts of CVE-2024-27931 include the risk of creating files outside allowed directories, which may overwrite important system files.

5

Who is impacted by CVE-2024-27931?

Any user utilizing the Deno runtime version prior to 1.41.1 is potentially impacted by CVE-2024-27931.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203