CVE-2021-41641 Information

Description

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access the Deno.symlink method can be used to gain access to any directory.

Reference

https://hackers.report/report/614876917a7b150012836bb8 https://github.com/denoland/deno/issues/12152

Share on: