## Summary In Deno, environment access is gated by the `env` permission. You can deny it with `--deny-env`, or restrict it to a specific allowlist with `--allow-env=FOO,BAR`. The expectation is that a program running without `env` permission cannot change `process.env`. `process.loadEnvFile()` (the Node-compatible API for loading variables from a `.env` file) does **not** honor this. It only checks that the program has **read** permission for the dotenv file, then writes every key in that file into the process environment — even when `env` access is denied. In effect, **`--allow-read` plus a writable or attacker-controlled `.env` file is enough to defeat `--deny-env`.** ## Am I affected? You are potentially affected if **all** of the following are true: 1. You run Deno **v2.3.0 or newer**. 2. Your program (or any dependency it imports) calls `process.loadEnvFile()` from `node:process`. 3. You rely on Deno's permission model — specifically `--deny-env`, an `--allow-env=…` allowlist, or running without granting `env` — as a security boundary. 4. The `.env` path passed to `loadEnvFile()` can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your `--allow-read` grant. If your program does not use `process.loadEnvFile()` at all, or if it already grants full `env` access, this advisory does not change your risk.
## Summary In Deno, environment access is gated by the `env` permission. You can deny it with `--deny-env`, or restrict it to a specific allowlist with `--allow-env=FOO,BAR`. The expectation is that a program running without `env` permission cannot change `process.env`. `process.loadEnvFile()` (the Node-compatible API for loading variables from a `.env` file) does **not** honor this. It only checks that the program has **read** permission for the dotenv file, then writes every key in that file into the process environment — even when `env` access is denied. In effect, **`--allow-read` plus a writable or attacker-controlled `.env` file is enough to defeat `--deny-env`.** ## Am I affected? You are potentially affected if **all** of the following are true: 1. You run Deno **v2.3.0 or newer**. 2. Your program (or any dependency it imports) calls `process.loadEnvFile()` from `node:process`. 3. You rely on Deno's permission model — specifically `--deny-env`, an `--allow-env=…` allowlist, or running without granting `env` — as a security boundary. 4. The `.env` path passed to `loadEnvFile()` can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your `--allow-read` grant. If your program does not use `process.loadEnvFile()` at all, or if it already grants full `env` access, this advisory does not change your risk.
Update deno to 2.8.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDeno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access affects deno (rust). Severity is medium. ## Summary In Deno, environment access is gated by the `env` permission. You can deny it with `--deny-env`, or restrict it to a specific allowlist with `--allow-env=FOO,BAR`. The expectation is that a program running without `env` permission cannot change `process.env`. `process.loadEnvFile()` (the Node-compatible API for loading variables from a `.env` file) does **not** honor this. It only checks that the program has **read** permission for the dotenv file, then writes every key in that file into the process environment — even when `env` access is denied. In effect, **`--allow-read` plus a writable or attacker-controlled `.env` file is enough to defeat `--deny-env`.** ## Am I affected? You are potentially affected if **all** of the following are true: 1. You run Deno **v2.3.0 or newer**. 2. Your program (or any dependency it imports) calls `process.loadEnvFile()` from `node:process`. 3. You rely on Deno's permission model — specifically `--deny-env`, an `--allow-env=…` allowlist, or running without granting `env` — as a security boundary. 4. The `.env` path passed to `loadEnvFile()` can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your `--allow-read` grant. If your program does not use `process.loadEnvFile()` at all, or if it already grants full `env` access, this advisory does not change your risk.
AI coding agents often install or upgrade packages automatically in rust. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| denorust | <=2.8.0 | 2.8.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate deno to 2.8.1 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanDeno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access affects deno (rust). Severity is medium. ## Summary In Deno, environment access is gated by the `env` permission. You can deny it with `--deny-env`, or restrict it to a specific allowlist with `--allow-env=FOO,BAR`. The expectation is that a program running without `env` permission cannot change `process.env`. `process.loadEnvFile()` (the Node-compatible API for loading variables from a `.env` file) does **not** honor this. It only checks that the program has **read** permission for the dotenv file, then writes every key in that file into the process environment — even when `env` access is denied. In effect, **`--allow-read` plus a writable or attacker-controlled `.env` file is enough to defeat `--deny-env`.** ## Am I affected? You are potentially affected if **all** of the following are true: 1. You run Deno **v2.3.0 or newer**. 2. Your program (or any dependency it imports) calls `process.loadEnvFile()` from `node:process`. 3. You rely on Deno's permission model — specifically `--deny-env`, an `--allow-env=…` allowlist, or running without granting `env` — as a security boundary. 4. The `.env` path passed to `loadEnvFile()` can be controlled or modified by a less-trusted party (untrusted input, user-writable directory, third-party dependency, etc.) and is covered by your `--allow-read` grant. If your program does not use `process.loadEnvFile()` at all, or if it already grants full `env` access, this advisory does not change your risk.
AI coding agents often install or upgrade packages automatically in rust. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| denorust | <=2.8.0 | 2.8.1 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard