PoC Index

CVE-2021-41641

HIGH 8.4EPSS 0.4%

Deno <=1.14.0 file sandbox does not handle symbolic links correctly. When running Deno with specific write access, the Deno.symlink method can be used to gain access to any directory.

CVSS v3.1
8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS v3.1
8.4 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
CVSS v2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.38% chance of exploitation in the next 30 days, 31th percentile
Published
2022-06-12
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related