CVE-2026-49406 | denoland deno up to 2.7.11 Resolver package.json path traversal (GHSA-968w-xfqw-vp9q)
A vulnerability has been found in denoland deno up to 2.7.11 and classified as critical. The affected element is an unknown function of the file package.json of the component Resolver. Performing a manipulation results in path traversal.
This vulnerability is known as CVE-2026-49406. Attacking locally is a requirement. No exploit is available.
The affected component should be upgraded.