GHSA-4c8g-jvcx-v4hv

Suggest an improvement
Source
https://github.com/advisories/GHSA-4c8g-jvcx-v4hv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4c8g-jvcx-v4hv/GHSA-4c8g-jvcx-v4hv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4c8g-jvcx-v4hv
Aliases
Downstream
Published
2026-06-16T19:04:57Z
Modified
2026-07-20T21:15:26Z
Severity
  • 5.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access
Details

Summary

In Deno, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist with --allow-env=FOO,BAR. The expectation is that a program running without env permission cannot change process.env.

process.loadEnvFile() (the Node-compatible API for loading variables from a .env file) does not honor this. It only checks that the program has read permission for the dotenv file, then writes every key in that file into the process environment — even when env access is denied.

In effect, --allow-read plus a writable or attacker-controlled .env file is enough to defeat --deny-env.

Am I affected?

You are potentially affected if all of the following are true:

  1. You run Deno v2.3.0 or newer.
  2. Your program (or any dependency it imports) calls process.loadEnvFile() from node:process.
  3. You rely on Deno's permission model — specifically --deny-env, an --allow-env=… allowlist, or running without granting env — as a security boundary.
  4. The .env path passed to loadEnvFile() can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your --allow-read grant.

If your program does not use process.loadEnvFile() at all, or if it already grants full env access, this advisory does not change your risk.

Database specific
{
    "cwe_ids":  [
        "CWE-863"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-16T19:04:57Z",
    "nvd_published_at":  "2026-06-23T18:18:04Z",
    "severity":  "MODERATE"
}
References

Affected packages

crates.io / deno

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.8.1

Database specific

last_known_affected_version_range
"<= 2.8.0"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4c8g-jvcx-v4hv/GHSA-4c8g-jvcx-v4hv.json"