SB2023011793 - Improper Neutralization of Escape, Meta, or Control Sequences in Deno



SB2023011793 - Improper Neutralization of Escape, Meta, or Control Sequences in Deno

Published: January 17, 2023 Updated: April 23, 2026

Security Bulletin ID SB2023011793
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper Neutralization of Escape, Meta, or Control Sequences (CVE-ID: CVE-2023-22499)

The vulnerability allows a remote attacker to spoof an interactive permission prompt.

The vulnerability exists due to improper neutralization of terminal output in the interactive permission prompt when handling multithreaded program output. A remote attacker can clear the terminal screen and rewrite the displayed prompt to spoof an interactive permission prompt.

User interaction is required, and the issue affects environments that attach an interactive prompt, including programs using the Web Worker API.


Remediation

Install update from vendor's website.