CVE-2026-103473
Received Received - Intake

Command Injection in Deno on Windows via Node Child Process

Vulnerability report for CVE-2026-103473, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: VulnCheck

Description

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
deno deno From 2.7.0 (inc) to 2.9.7 (inc)
denoland deno From 2.7.0 (inc) to 2.9.7 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects Deno versions 2.7.0 through 2.9.7 on Windows. It is a command injection issue in the node:child_process module where shell arguments are incorrectly escaped for the wrong shell type. Attackers can exploit this by passing untrusted arguments with the shell option, enabling arbitrary OS command execution with Deno process privileges.

Detection Guidance

Check Deno version on Windows systems with 'deno --version'. If version is between 2.7.0 and 2.9.7, the system is vulnerable. Review applications using node:child_process with shell option for untrusted input handling.

Impact Analysis

If you use Deno on Windows with versions 2.7.0 through 2.9.7, an attacker could execute arbitrary commands on your system with the same privileges as the Deno process. This could lead to data theft, system compromise, or further network attacks depending on the Deno application's environment.

Compliance Impact

This vulnerability could lead to unauthorized command execution, potentially violating data protection requirements under GDPR or HIPAA if sensitive data is accessed or modified. Organizations using affected Deno versions may face compliance violations due to insufficient input validation and privilege management.

Mitigation Strategies

Upgrade Deno to version 2.9.8 or later. Avoid using shell option with node:child_process for untrusted input. Implement strict input validation for all command arguments.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103473. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart