{"id":"CVE-2021-42139","details":"Deno Standard Modules before 0.107.0 allows Code Injection via an untrusted YAML file in certain configurations.","modified":"2026-07-09T03:25:07.491697Z","published":"2021-10-11T05:15:06.827Z","references":[{"type":"ADVISORY","url":"https://github.com/denoland/deno_std/releases/tag/0.107.0"},{"type":"ADVISORY","url":"https://vuln.ryotak.me/advisories/58"},{"type":"EVIDENCE","url":"https://github.com/denoland/deno_std/pull/1275"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/denoland/std","events":[{"introduced":"0"},{"fixed":"197bb8c295034be7d00842623b417c7a7bdce711"}],"database_specific":{"cpe":"cpe:2.3:a:deno:deno_standard_modules:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.107.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["0.106.0","0.105.0","0.104.0","0.103.0","0.102.0","0.101.0","0.100.0","0.99.0","0.98.0","0.97.0","0.96.0","0.95.0","0.94.0","0.93.0","0.92.0","0.91.0","0.90.0","0.89.0","0.88.0","0.87.0","0.86.0","0.85.0","v0.20.0","v0.19.0","v0.18.0","v0.17.0","v0.16.0","v0.15.0","v0.12.0","v0.11.0","v0.10.0","v0.9.0","v0.8.0","v0.7.0","v0.6.0","20190520","20190516","v0.5.0","v0.4.0","v0.3.10","v0.3.8","v0.3.6","v0.3.5","v0.3.4","v0.3.3","v0.3.2","v0.3.1","v0.3.0","v0.2.11","v0.2.10","v0.2.9","v0.2.8","v0.2.7","v0.2.6","v0.2.5","v0.2.4","v0.2.3","v0.2.2","v0.2.1","v0.2.0","v0.1.12","v0.1.11"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-42139.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}