CVE-2026-103473: Deno 2.7.0 through 2.9.7 Command Injection via node:child_process
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:childprocess where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed?
The issue affects Deno versions 2.7.0 through 2.9.7 running on Windows. It applies to code using node:child_process with the shell option.
What must an attacker control to exploit this?
An attacker needs to be able to supply untrusted arguments to a node:child_process invocation that enables the shell option. Those arguments can then be used to inject operating-system commands.
What is the impact of successful exploitation?
Successful exploitation allows arbitrary command execution with the privileges of the Deno process. Confidentiality, integrity, and availability may all be affected.