CVE-2025-48934: Deno.env.toObject() ignores the variables listed in --deny-env and returns all environment variables
Summary The Deno.env.toObject method ignores any variables listed in the --deny-env option of the deno run command. When looking at the documentation of the --deny-env option this might lead to a false impression that variables listed in the option are impossible to read.
PoC
export AWSSECRETACCESSKEY=my-secret-aws-key
Works as expected. The program stops with a "NotCapable" error message echo 'console.log(Deno.env.get("AWSSECRETACCESSKEY"));' | deno run \ --allow-env \ --deny-env=AWSACCESSKEYID,AWSSECRETACCESSKEY -
All enviroment variables are printed and the --deny-env list is completely disregarded echo 'console.log(Deno.env.toObject());' | deno run \ --allow-env \ --deny-env=AWSACCESSKEYID,AWSSECRETACCESSKEY -
The first example using get exits with the following error: error: Uncaught (in promise) NotCapable: Requires env access to "AWSSECRETACCESSKEY", run again with the --allow-env flag console.log(Deno.env.get("AWSSECRETACCESSKEY")); ^ at Object.getEnv [as get] (ext:denoos/30os.js:124:10) at file:///$deno$stdin.mts:1:22
The second example using toObject prints all environment variables: [Object: null prototype] { ... AWSSECRETACCESSKEY: "my-secret-aws-key", ... }
Impact Software relying on the combination of both flags to allow access to most environment variables except a few sensitive ones will be vulnerable to malicious code trying to steal secrets using the Deno.env.toObject() method.
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to versions 2.1.13 and 2.2.13, the Deno.env.toObject method ignores any variables listed in the --deny-env option of the deno run command. When looking at the documentation of the --deny-env option this might lead to a false impression that variables listed in the option are impossible to read. Software relying on the combination of both flags to allow access to most environment variables except a few sensitive ones will be vulnerable to malicious code trying to steal secrets using the Deno.env.toObject() method. Versions 2.1.13 and 2.2.13 contains a patch.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48934?
CVE-2025-48934 is considered a moderate severity vulnerability due to its potential exposure of sensitive environment variables.
How do I fix CVE-2025-48934?
To fix CVE-2025-48934, upgrade to Deno version 2.1.13 or 2.2.13 or later.
What is the impact of CVE-2025-48934?
The impact of CVE-2025-48934 includes the unintended leakage of environment variables that should be restricted.
Which versions of Deno are affected by CVE-2025-48934?
Versions of Deno prior to 2.1.13 and 2.2.13 are affected by CVE-2025-48934.
What does the `Deno.env.toObject` method do in relation to CVE-2025-48934?
In relation to CVE-2025-48934, the `Deno.env.toObject` method improperly ignores security restrictions from the `--deny-env` option.