CVE-2026-103473High· 8.1▾ TwilightDeno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44726High· 7.4Deno's TLS retry copies stale upgrade hook, risking plaintext traffic
CVE-2021-32619Critical· 9.8Deno's static imports inside dynamically imported modules do not adhere to permission checks
CVE-2026-49402High· 8.1Deno: Command Injection via spawnSync & spawn on Windows
CVE-2026-49859Medium· 5.2Deno: `fetch()` API sandbox bypass via missing DNS resolution check
CVE-2026-49860Medium· 5.2Deno: WebSocket API sandbox bypass via missing post-DNS check
CVE-2026-49440High· 7.4Deno: Miller-Rabin Primality Test Allows Zero Rounds