Skip to content
Critical Command Injection Vulnerability in Deno Versions 2.7.0 to 2.9.7

Critical Command Injection Vulnerability in Deno Versions 2.7.0 to 2.9.7

First seen 1 Oct 2026, 01:58 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 01:59 UTC
  • •CVE-2026-103473 affects Deno versions 2.7.0 to 2.9.7 on Windows.
  • •The vulnerability allows command injection through improperly escaped shell arguments.
  • •Users should upgrade to a fixed version and avoid untrusted input in subprocess calls.

A command injection vulnerability (CVE-2026-103473) has been identified in Deno versions 2.7.0 through 2.9.7 on Windows. This flaw allows attackers to execute arbitrary OS commands via improperly escaped shell arguments in node:child_process. The risk is particularly high for Windows-hosted services and automation workers using JavaScript/TypeScript. Exploitation requires specific vulnerable call paths, but the complexity is high. The vulnerability was published on September 30, 2026, with a CVSS score of 9.2, classifying it as critical. No proof-of-concept or has been confirmed yet. Affected users are advised to upgrade to a patched version and avoid using untrusted input in shell-enabled calls until then.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-30
CVE-2026-103473 published
A critical command injection vulnerability in Deno was disclosed, affecting versions 2.7.0 to 2.9.7.
Redpacketsecurity
2026-10-01
Vulnerability awareness raised
Security advisories highlight the critical nature of the command injection vulnerability in Deno.
www.vulncheck.com

More articles in this cluster (2)

Following this threat?

Track CVE-2026-103473 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions of Deno are affected?
Deno versions 2.7.0 through 2.9.7 on Windows are affected by this vulnerability.
Is there a patch available?
Yes, users should upgrade to a vendor-fixed release to mitigate the vulnerability.
What should I do if I can't upgrade immediately?
Avoid using shell-enabled calls with untrusted input and restrict permissions for the runtime service account.