PT-2026-103498 · Deno · Deno

·

CVE-2026-103473

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deno versions 2.7.0 through 2.9.7
Description On Windows, a command injection issue exists in the node:child process module. The escapeShellArg() function incorrectly applies POSIX rules instead of Windows cmd.exe rules, which fails to neutralize metacharacters. This allows attackers to execute arbitrary OS commands with the privileges of the Deno process by passing untrusted arguments when using the shell option.
Recommendations Update Deno to a version later than 2.9.7.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103473

Affected Products

Deno