Command Injection Vulnerability in Deno Runtime by Deno
CVE-2026-27190

8.1HIGH

Key Information:

Vendor

Denoland

Status
Vendor
CVE Published:
20 February 2026

What is CVE-2026-27190?

A command injection vulnerability exists in the Deno runtime's implementation of node:child_process, allowing attackers to execute arbitrary commands on the host system. This issue has been addressed in version 2.6.8, which is crucial for safeguarding applications that utilize Deno for JavaScript, TypeScript, and WebAssembly execution.

Affected Version(s)

deno < 2.6.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.