{"id":"CVE-2021-32619","details":"Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission checks when statically importing other modules. The vulnerability has been patched in Deno release 1.10.2.","aliases":["GHSA-xpwj-7v8q-mcgj"],"modified":"2026-08-07T17:02:07.752260Z","published":"2021-05-28T21:15:08.893Z","references":[{"type":"ADVISORY","url":"https://github.com/denoland/deno/security/advisories/GHSA-xpwj-7v8q-mcgj"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/denoland/deno","events":[{"introduced":"dd01f206da0b7e1b305e70cdd3c98bf60fbefc5d"},{"fixed":"232ec7798c5ee38e645c2aea31aea3e9a81e17f3"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.5.0"},{"fixed":"1.10.2"}]}}],"versions":["v1.10.1","v1.10.0","v1.9.2","v1.9.1","v1.9.0","v1.8.2","v1.8.1","v1.8.0","v1.7.4","v1.7.3","v1.7.2","v1.7.1","std/0.85.0","v1.7.0","std/0.84.0","v1.6.3","std/0.83.0","v1.6.2","std/0.82.0","v1.6.1","std/0.81.0","v1.6.0","std/0.80.0","v1.5.4","std/0.79.0","v1.5.3","std/0.78.0","v1.5.2","std/0.77.0","v1.5.1","std/0.76.0","v1.5.0","std/0.75.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-32619.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}