CVE-2026-22864: Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
Summary A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.).
POC javascript const command = new Deno.Command('./test.BAT', { args: ['&calc.exe'], }); const child = command.spawn(); This causes calc.exe to be launched; see the attached screenshot for evidence.
Patched in CVE-2025-61787 — prevents execution of .bat and .cmd files: !photo2025-10-10 02 27 23
Bypass of the patched vulnerability: !photo2025-10-10 02 27 25
Impact The script launches calc.exe on Windows, demonstrating that passing user-controlled arguments to a spawned batch script can result in command-line injection.
Mitigation
Users should update to Deno v2.5.6 or newer.
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.). This vulnerability is fixed in 2.5.6.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22864?
The severity of CVE-2026-22864 is rated as moderate due to the incomplete fix for command-injection prevention.
How do I fix CVE-2026-22864?
To fix CVE-2026-22864, upgrade to Deno version 2.5.6 or later where the vulnerability is addressed.
What systems are affected by CVE-2026-22864?
CVE-2026-22864 affects Deno versions prior to 2.5.6 on Windows systems.
What is the nature of the vulnerability in CVE-2026-22864?
CVE-2026-22864 involves an incomplete implementation of command-injection prevention that allows for case-insensitive extension bypass.
Are there any workarounds for CVE-2026-22864?
There are no official workarounds for CVE-2026-22864; upgrading to a secure version is recommended.