CVE-2026-49983: Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access

Published Jun 16, 2026
·
Updated

Summary

In Deno, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env permission cannot change process.env.

process.loadEnvFile() (the Node-compatible API for loading variables from a .env file) does not honor this. It only checks that the program has read permission for the dotenv file, then writes every key in that file into the process environment — even when env access is denied.

In effect, --allow-read plus a writable or attacker-controlled .env file is enough to defeat --deny-env.

Am I affected?

You are potentially affected if all of the following are true:

1. You run Deno v2.3.0 or newer. 2. Your program (or any dependency it imports) calls process.loadEnvFile() from node:process. 3. You rely on Deno's permission model — specifically --deny-env, an --allow-env=… allowlist, or running without granting env — as a security boundary. 4. The .env path passed to loadEnvFile() can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your --allow-read grant.

If your program does not use process.loadEnvFile() at all, or if it already grants full env access, this advisory does not change your risk.

Other sources

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env permission cannot change process.env. process.loadEnvFile() (the Node-compatible API for loading variables from a .env file) does not honor this. It only checks that the program has read permission for the dotenv file, then writes every key in that file into the process environment — even when env access is denied. In effect, --allow-read plus a writable or attacker-controlled .env file is enough to defeat --deny-env. This vulnerability is fixed in 2.8.1.

— MITRE

Affected Software

2 affected componentsFixes available
rust/deno<=2.8.0
2.8.1
Deno Deno>=2.3.0<2.8.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade rust/deno to a version that resolves this vulnerability.

    Fixed in 2.8.1
  2. Upgrade

    Upgrade Deno to a version that resolves this vulnerability.

    Fixed in 2.8.1
  3. Configuration

    When using Deno's permission model, prefer restricting environment access with `--allow-env=FOO,BAR` rather than relying on `--deny-env`; note that `process.loadEnvFile()` can defeat `--deny-env` if a writable or attacker-controlled `.env` file is reachable via `--allow-read`.

    Deno permissions --allow-env = FOO,BAR
  4. Compensating control

    If your program or any dependency calls `process.loadEnvFile()` and you must use `--allow-read`, ensure the `.env` path/file is not writable or attacker-controlled (e.g., not in a user-writable directory or otherwise untrusted location), since `process.loadEnvFile()` only requires read permission and then writes every key into `process.env` even when `--deny-env` is set.

Event History

Jun 16, 2026
Advisory Published
via GitHub·07:04 PM
Data Sourced
via GitHub·07:04 PM
DescriptionSeverityWeaknessAffected Software
Jun 23, 2026
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-49983?

CVE-2026-49983 has a medium severity rating of 5.2.

2

How do I fix CVE-2026-49983?

To mitigate CVE-2026-49983, ensure that environment access is restricted by using the --deny-env or --allow-env=FOO,BAR flags in Deno.

3

What software is affected by CVE-2026-49983?

CVE-2026-49983 affects the Deno runtime environment.

4

What is the risk level of CVE-2026-49983?

CVE-2026-49983 has a risk level of 32, indicating a moderate threat.

5

What does CVE-2026-49983 affect?

CVE-2026-49983 affects the environment variable handling in Deno, potentially allowing unauthorized changes to process.env.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203