CVE-2025-48935
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Starting in version 2.2.0 and prior to versions 2.2.5, it is possible to bypass Deno's permission read/write db permission check by using ATTACH DATABASE statement. Version 2.2.5 contains a patch for the issue.
CRITICAL · CVSS 9.1
EPSS 0.00349
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0