www.vulncheck.com Critical Command Injection Vulnerability in Deno Versions 2.7.0 to 2.9.7
Article Content
- •CVE-2026-103473 affects Deno versions 2.7.0 to 2.9.7 on Windows.
- •The vulnerability allows command injection through improperly escaped shell arguments.
- •Users should upgrade to a fixed version and avoid untrusted input in subprocess calls.
A command injection vulnerability (CVE-2026-103473) has been identified in Deno versions 2.7.0 through 2.9.7 on Windows. This flaw allows attackers to execute arbitrary OS commands via improperly escaped shell arguments in node:child_process. The risk is particularly high for Windows-hosted services and automation workers using JavaScript/TypeScript. Exploitation requires specific vulnerable call paths, but the complexity is high. The vulnerability was published on September 30, 2026, with a CVSS score of 9.2, classifying it as critical. No proof-of-concept or has been confirmed yet. Affected users are advised to upgrade to a patched version and avoid using untrusted input in shell-enabled calls until then.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-103473 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions of Deno are affected?
Is there a patch available?
What should I do if I can't upgrade immediately?
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…