CVE-2025-61787High· 8.1▾ TwilightDeno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly sp…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.4 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
2.1%
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, CreateProcess() always implicitly spawns cmd.exe if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
deno <= 2.2.15deno >= 2.3.0, < 2.5.3Upgrade past the affected range:
deno 2.5.3Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61786Low· 3.3Deno is a JavaScript, TypeScript, and WebAssembly runtime
CVE-2025-61785Low· 3.3Deno is a JavaScript, TypeScript, and WebAssembly runtime
CVE-2026-103473High· 8.1Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type
CVE-2026-44726High· 7.4Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
CVE-2021-32619Critical· 9.8Deno's static imports inside dynamically imported modules do not adhere to permission checks
CVE-2026-49859Medium· 5.2Deno: `fetch()` API sandbox bypass via missing DNS resolution check