CVE-2025-48935

CRITICAL

Deno 2.2.0-2.2.5 - Incorrect Authorization via ATTACH DATABASE Statement

Title source: llm
STIX 2.1

Description

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using `ATTACH DATABASE` statement. Version 2.2.5 contains a patch for the issue.

Scores

CVSS v3 9.1
EPSS 0.0041
EPSS Percentile 32.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (3)
crates.io/deno 2.2.0 - 2.2.5crates.io
crates.io/deno_node 0.129.0 - 0.134.0crates.io
deno/deno 2.2.0 - 2.2.5
Published Jun 04, 2025
Tracked Since Feb 18, 2026