---
id: CVE-2025-61787
title: 'Deno is a JavaScript, TypeScript, and WebAssembly runtime'
summary: >-
  Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to
  2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows
  when batch files are executed. In Windows, ``CreateProcess()`` always
  implicitly sp…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-77
vendor: deno
product: deno
affected:
  - deno <= 2.2.15
  - 'deno >= 2.3.0, < 2.5.3'
patched:
  - deno 2.5.3
published: '2025-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61787'
references:
  - url: >-
      https://github.com/denoland/deno/commit/8a0990ccd37bafd8768176ca64b906ba2da2d822
    label: security-advisories@github.com
  - url: 'https://github.com/denoland/deno/pull/30818'
    label: security-advisories@github.com
  - url: 'https://github.com/denoland/deno/releases/tag/v2.2.15'
    label: security-advisories@github.com
  - url: 'https://github.com/denoland/deno/releases/tag/v2.5.3'
    label: security-advisories@github.com
  - url: 'https://github.com/denoland/deno/security/advisories/GHSA-m2gf-x3f6-8hq3'
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.02084
epssPercentile: 0.80967
ingestedAt: '2026-10-08T13:42:54.991Z'
---

## Overview

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.

## Affected

- `deno <= 2.2.15`
- `deno >= 2.3.0, < 2.5.3`

## Remediation

Upgrade past the affected range:

- `deno 2.5.3`
