Improper access control in Deno - CVE-2025-48934
Published: April 23, 2026
Deno
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in Deno.env.toObject() when enumerating environment variables under a --deny-env restriction. A remote user can execute malicious code that calls Deno.env.toObject() to disclose sensitive information.
The issue affects programs that rely on --allow-env together with --deny-env to block access to selected environment variables.