{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adenodeno2.9.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:deno:deno:2.7.0:*:*:*:*:*:*:*","cpe:2.3:a:deno:deno:2.9.7:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-103473"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Deno (2.7.0 through 2.9.7)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","command-injection","deno","windows"],"_cs_type":"advisory","_cs_vendors":["Deno"],"content_html":"\u003cp\u003eDeno versions 2.7.0 through 2.9.7 on Windows contain a critical command injection vulnerability within the built-in node:child_process module. This flaw occurs because the implementation fails to correctly escape shell arguments when the shell option is enabled, causing the environment to process inputs for the incorrect shell type. An attacker capable of influencing the arguments passed to a child process via this module can escape the intended command context to execute arbitrary operating system commands. This execution occurs with the same privileges as the Deno runtime process. This vulnerability is particularly impactful for server-side applications, build tools, or automated workflows written in Deno that process external or untrusted data using the child_process spawning utilities.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for unauthorized arbitrary command execution on the host Windows system. This could lead to full system compromise, data exfiltration, or lateral movement depending on the service account context running the Deno application. Organizations using these specific Deno versions on Windows should prioritize upgrading to a patched release.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all Deno instances on Windows to version 2.9.8 or later, where the shell argument escaping logic has been corrected.\u003c/li\u003e\n\u003cli\u003eAudit Deno application codebases to identify instances where the node:child_process module is used with the 'shell' option and where untrusted input is passed to the argument array.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege by running Deno processes under service accounts with limited filesystem and network permissions to mitigate the impact of potential command injection.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T18:36:27Z","date_published":"2026-09-30T18:36:27Z","id":"https://feed.craftedsignal.io/briefs/2026-09-deno-command-injection/","summary":"Deno versions 2.7.0 through 2.9.7 on Windows are vulnerable to command injection in the node:child_process module due to improper shell argument escaping.","title":"Command Injection in Deno node:child_process Module","url":"https://feed.craftedsignal.io/briefs/2026-09-deno-command-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:deno:deno:2.9.7:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}