Command Injection Vulnerability in Deno by DenoLand on Windows
CVE-2026-103473

9.2CRITICAL

Key Information:

Vendor

Denoland

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-103473?

Versions 2.7.0 to 2.9.7 of Deno for Windows are vulnerable to a command injection flaw within the node:child_process module. This vulnerability arises from the improper handling of shell arguments, allowing attackers to execute arbitrary OS commands by supplying untrusted arguments alongside the shell option. An exploit could allow malicious entities to execute commands with the privileges of the Deno process, posing significant security risks.

Affected Version(s)

deno 2.7.0 <= 2.9.7

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

PVUDivakar
.