{"id":"CVE-2021-32619","aliases":["GHSA-xpwj-7v8q-mcgj"],"url":"https://o3.security/vulnerability/CVE-2021-32619","summary":"Deno's static imports inside dynamically imported modules do not adhere to permission checks","details":"Deno is a runtime for JavaScript and TypeScript that uses V8 and is built in Rust. In Deno versions 1.5.0 to 1.10.1, modules that are dynamically imported through `import()` or `new Worker` might have been able to bypass network and file system permission checks when statically importing other modules. The vulnerability has been patched in Deno release 1.10.2.","published":"2021-05-28T21:15:08.893Z","modified":"2026-08-07T17:02:07.752260Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":{"score":0.01113,"percentile":0.63016,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"deno","fixedVersion":"1.10.2"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/denoland/deno/security/advisories/GHSA-xpwj-7v8q-mcgj"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:02:07.752260Z"}}