Product
Deno versions 2.7.0 through 2.9.7 on Windows are vulnerable to command injection in the node:child_process module due to improper shell argument escaping.