DEV Community

threataft
threataft

Posted on Originally published at threataft.com

Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows

If your Deno app on Windows passes untrusted input to spawn, spawnSync, or exec with shell: true — patch now.

CVE-2026-103473 (CVSS 8.1) is a command injection vulnerability in Deno's node:child_process polyfill. The escapeShellArg() helper applies POSIX-style escaping, but on Windows the arguments land in cmd.exe — which has completely different rules. Two problems:

  1. cmd.exe metacharacters (&, |, &&, ||, ;) aren't quoted
  2. %VAR% is expanded by cmd.exe even inside double-quoted strings — POSIX escaping doesn't cover this at all

Inject either into a controlled argument and you're executing arbitrary commands with the Deno process's privileges.

Affected: Deno 2.7.0 – 2.9.7 on Windows

Fixed: Deno 2.9.8+

Quick audit — search your codebase for:


js
spawn(..., { shell: true })
spawnSync(..., { shell: true })
exec(...)  // shell: true is the default

// Instead of this (vulnerable on Windows):
exec(`convert ${userInput}`, callback);

// Use this (no shell interpretation):
spawn('convert', [userInput], { shell: false });
Enter fullscreen mode Exit fullscreen mode

Top comments (0)