Deno CVE-2026-103473: CVSS 8.1 command injection in node:child_process on Windows
Deno 2.7.0–2.9.7 on Windows is affected by a command injection flaw (CVSS 8.1) in the node:child_process polyfill: escapeShellArg() uses POSIX-style escaping, but arguments reach cmd.exe, which follows different rules. The issue is fixed in Deno 2.9.8.
- Affected: Deno 2.7.0–2.9.7 on Windows; fixed in 2.9.8+
- cmd.exe metacharacters (&, |, &&, ||, ;) are not quoted
- cmd.exe expands %VAR% even inside double-quoted strings
- Risk applies to spawn, spawnSync and exec with shell: true
Read next
Software