<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:deno:deno:2.9.7:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3adenodeno2.9.7/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 18:36:27 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3adenodeno2.9.7/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Command Injection in Deno node:child_process Module</title><link>https://feed.craftedsignal.io/briefs/2026-09-deno-command-injection/</link><pubDate>Wed, 30 Sep 2026 18:36:27 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-deno-command-injection/</guid><description>Deno versions 2.7.0 through 2.9.7 on Windows are vulnerable to command injection in the node:child_process module due to improper shell argument escaping.</description><content:encoded><![CDATA[<p>Deno versions 2.7.0 through 2.9.7 on Windows contain a critical command injection vulnerability within the built-in node:child_process module. This flaw occurs because the implementation fails to correctly escape shell arguments when the shell option is enabled, causing the environment to process inputs for the incorrect shell type. An attacker capable of influencing the arguments passed to a child process via this module can escape the intended command context to execute arbitrary operating system commands. This execution occurs with the same privileges as the Deno runtime process. This vulnerability is particularly impactful for server-side applications, build tools, or automated workflows written in Deno that process external or untrusted data using the child_process spawning utilities.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for unauthorized arbitrary command execution on the host Windows system. This could lead to full system compromise, data exfiltration, or lateral movement depending on the service account context running the Deno application. Organizations using these specific Deno versions on Windows should prioritize upgrading to a patched release.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all Deno instances on Windows to version 2.9.8 or later, where the shell argument escaping logic has been corrected.</li>
<li>Audit Deno application codebases to identify instances where the node:child_process module is used with the 'shell' option and where untrusted input is passed to the argument array.</li>
<li>Apply the principle of least privilege by running Deno processes under service accounts with limited filesystem and network permissions to mitigate the impact of potential command injection.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>command-injection</category><category>deno</category><category>windows</category></item></channel></rss>