PT-2026-103498 · Deno · Deno
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Deno versions 2.7.0 through 2.9.7
Description
On Windows, a command injection issue exists in the
node:child process module. The escapeShellArg() function incorrectly applies POSIX rules instead of Windows cmd.exe rules, which fails to neutralize metacharacters. This allows attackers to execute arbitrary OS commands with the privileges of the Deno process by passing untrusted arguments when using the shell option.Recommendations
Update Deno to a version later than 2.9.7.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deno