Deno CVE-2026-103473 — CVSS 8.1 Command Injection in node:child_process on Windows
If your Deno app on Windows passes untrusted input to spawn, spawnSync, or exec with shell: true — patch now. CVE-2026-103473 (CVSS 8.1) is a command injection vulnerability in Deno's node:child_process polyfill. The es
If your Deno app on Windows passes untrusted input to spawn, spawnSync, or exec with shell: true — patch now.
CVE-2026-103473 (CVSS 8.1) is a command injection vulnerability in Deno's node:child_process polyfill. The escapeShellArg() helper applies POSIX-style escaping, but on Windows the arguments land in cmd.exe — which has completely different rules. Two problems:
- cmd.exe metacharacters (
&,|,&&,||,;) aren't quoted -
%VAR%is expanded by cmd.exe even inside double-quoted strings — POSIX escaping doesn't cover this at all
Inject either into a controlled argument and you're executing arbitrary commands with the Deno process's privileges.
Affected: Deno 2.7.0 – 2.9.7 on Windows
Fixed: Deno 2.9.8+
Quick audit — search your codebase for:
js
spawn(..., { shell: true })
spawnSync(..., { shell: true })
exec(...) // shell: true is the default
// Instead of this (vulnerable on Windows):
exec(`convert ${userInput}`, callback);
// Use this (no shell interpretation):
spawn('convert', [userInput], { shell: false });
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.