Command Injection Vulnerability in Deno Runtime by Deno
CVE-2026-27190
8.1HIGH
What is CVE-2026-27190?
A command injection vulnerability exists in the Deno runtime's implementation of node:child_process, allowing attackers to execute arbitrary commands on the host system. This issue has been addressed in version 2.6.8, which is crucial for safeguarding applications that utilize Deno for JavaScript, TypeScript, and WebAssembly execution.
Affected Version(s)
deno < 2.6.8
