{"id":"GHSA-4c8g-jvcx-v4hv","summary":"Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access","details":"## Summary\n\nIn Deno, environment access is gated by the `env` permission. You can deny it\nwith `--deny-env`, or restrict it to a specific allowlist with\n`--allow-env=FOO,BAR`. The expectation is that a program running without `env`\npermission cannot change `process.env`.\n\n`process.loadEnvFile()` (the Node-compatible API for loading variables from a\n`.env` file) does **not** honor this. It only checks that the program has\n**read** permission for the dotenv file, then writes every key in that file\ninto the process environment — even when `env` access is denied.\n\nIn effect, **`--allow-read` plus a writable or attacker-controlled `.env` file\nis enough to defeat `--deny-env`.**\n\n## Am I affected?\n\nYou are potentially affected if **all** of the following are true:\n\n1. You run Deno **v2.3.0 or newer**.\n2. Your program (or any dependency it imports) calls `process.loadEnvFile()`\n   from `node:process`.\n3. You rely on Deno's permission model — specifically `--deny-env`, an\n   `--allow-env=…` allowlist, or running without granting `env` — as a\n   security boundary.\n4. The `.env` path passed to `loadEnvFile()` can be controlled or modified by\n   a less-trusted party (untrusted input, user-writable directory, third-party\n   dependency, etc.) and is covered by your `--allow-read` grant.\n\nIf your program does not use `process.loadEnvFile()` at all, or if it already\ngrants full `env` access, this advisory does not change your risk.","aliases":["CVE-2026-49983"],"modified":"2026-07-20T21:15:26.008803110Z","published":"2026-06-16T19:04:57Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-06-16T19:04:57Z","nvd_published_at":"2026-06-23T18:18:04Z","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/denoland/deno/security/advisories/GHSA-4c8g-jvcx-v4hv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-49983"},{"type":"PACKAGE","url":"https://github.com/denoland/deno"}],"affected":[{"package":{"name":"deno","ecosystem":"crates.io","purl":"pkg:cargo/deno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.8.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.8.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-4c8g-jvcx-v4hv/GHSA-4c8g-jvcx-v4hv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N"}]}