Deno · Deno · CVE-2026-103473
**Name of the Vulnerable Software and Affected Versions**
Deno versions 2.7.0 through 2.9.7
**Description**
On Windows, a command injection issue exists in the `node:child process` module. The `escapeShellArg()` function incorrectly applies POSIX rules instead of Windows `cmd.exe` rules, which fails to neutralize metacharacters. This allows attackers to execute arbitrary OS commands with the privileges of the Deno process by passing untrusted arguments when using the shell option.
**Recommendations**
Update Deno to a version later than 2.9.7.