chiprook
← Security
SecurityOctober 1, 2026, 08:44

Deno CVE-2026-103473: CVSS 8.1 command injection in node:child_process on Windows

Deno 2.7.0–2.9.7 on Windows is affected by a command injection flaw (CVSS 8.1) in the node:child_process polyfill: escapeShellArg() uses POSIX-style escaping, but arguments reach cmd.exe, which follows different rules. The issue is fixed in Deno 2.9.8.

Deno CVE-2026-103473: CVSS 8.1 command injection in node:child_process on Windows
#Deno#Windows
Read next
Software

Deno 2.6's Minimum Dependency Age Flag Ignores Year and Month Durations

Security

Cisco warns of active exploitation of CVSS 9.8 SD-WAN Manager auth bypass

Security

LightLLM hit by two CVSS 9.8 unauthenticated RCE flaws

Security

CVE-2026-75650 in Magento: 132,792 Matches and a 10.0 CVSS