---
id: CVE-2026-103473
title: >-
  Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection
  vulnerability in node:child_process where shell arguments are escaped for the
  wrong shell type
summary: >-
  Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection
  vulnerability in node:child_process where shell arguments are escaped for the
  wrong shell type. Attackers can inject OS commands by passing untrusted
  arguments with…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-78
vendor: denoland
product: deno
affected:
  - deno >= 2.7.0 <= 2.9.7
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T19:08:21.363'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-103473'
references:
  - url: 'https://github.com/denoland/deno'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1339
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1499
    label: disclosure@vulncheck.com
  - url: 'https://github.com/denoland/deno/pull/36772'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/deno-2.7.0-through-2.9.7-command-injection-via-node-child-process
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T18:17:24.547Z'
---

## Overview

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
