Description
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 1.41.3 and prior to versions 2.1.13, 2.2.13, and 2.3.2, `deno run --allow-read --deny-read main.ts` results in allowed, even though 'deny' should be stronger. The result is the same with all global unary permissions given as `--allow-* --deny-*`. This only affects a nonsensical combination of flags, so there shouldn't be a real impact on the userbase. Users may upgrade to version 2.1.13, 2.2.13, or 2.3.2 to receive a patch.
INFO
Published Date :
2025-06-04T19:15:55.041Z
Last Modified :
2025-06-04T19:32:53.261Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2025-48888 vulnerability.
| Vendors | Products |
|---|---|
| Deno |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-48888.