CVE-2025-61787: Deno is Vulnerable to Command Injection on Windows During Batch File Execution
Summary Deno versions up to 2.5.1 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.
Details In Windows, CreateProcess() always implicitly spawns cmd.exe if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows as demonstrated by the two proves-of-concept below.
PoC Using node:childprocess (with the env and run permissions): JS const { spawn } = require('node:childprocess'); const child = spawn('./test.bat', ['&calc.exe']); Using Deno.Command.spawn() (with the run permission): JS const command = new Deno.Command('./test.bat', { args: ['&calc.exe'], }); const child = command.spawn();
Impact Both of these scripts result in opening calc.exe on Windows, thus allowing a Command Line Injection attack when user-provided arguments are passed if the script being executed by the child process is a batch script.
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, CreateProcess() always implicitly spawns cmd.exe if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61787?
CVE-2025-61787 has been rated as moderately severe due to its potential for Command Line Injection attacks on Windows.
How do I fix CVE-2025-61787?
To fix CVE-2025-61787, upgrade Deno to version 2.5.3 or later, or 2.2.15 or later, to mitigate the vulnerability.
What versions are affected by CVE-2025-61787?
CVE-2025-61787 affects Deno versions prior to 2.5.3 and 2.2.15.
What kind of attacks can be executed due to CVE-2025-61787?
CVE-2025-61787 allows for Command Line Injection attacks when batch files are executed on Windows.
Is it safe to use Deno versions prior to 2.2.15 in production due to CVE-2025-61787?
No, using Deno versions prior to 2.2.15 in production is unsafe due to the risk of Command Line Injection attacks.