A critical command injection vulnerability has been identified in the Deno runtime on Windows host systems. Cataloged as CVE-2026-103473 and published under GitHub Security Advisory GHSA-m6mv-f8h2-2w86 with a maximum CVSS v3.1 base score of 9.8 (Critical), the flaw allows unauthenticated remote attackers to execute arbitrary operating system commands when applications invoke child process execution functions with uncurated arguments.

The Rise of Deno in Modern Cloud and Serverless Stacks

Deno has gained massive enterprise adoption as a secure-by-default JavaScript, TypeScript, and WebAssembly runtime, powering high-throughput backend services, CLI toolchains, and edge execution platforms such as Deno Deploy, Supabase Functions, and Netlify Edge. To ensure seamless interoperability with legacy npm packages, Deno maintains a comprehensive Node.js emulation layer, including node:child_process.

On Windows operating systems, process creation differs fundamentally from Unix POSIX semantics. Windows does not provide a native fork/exec model with discrete argument arrays; instead, the entire argument list is passed to CreateProcessW as a single command-line string, requiring runtime engines to accurately quote and escape command arguments.

Vulnerability Mechanics: Windows Shell Metacharacter Mismatch (CWE-78)

CVE-2026-103473 resides within Deno's internal argument serialization logic when invoking child processes with the shell: true configuration option on Windows:

// Vulnerable Application Pattern (Node.js compatibility mode)
import { spawn } from "node:child_process";

// Attacker-controlled user input passed to argument list
const userFileName = "report.txt & whoami > C:\pwned.txt";

// In vulnerable versions, Deno improperly escapes batch metacharacters
const child = spawn("notepad.exe", [userFileName], { shell: true });

When shell: true is specified on Windows, Deno passes the command string to cmd.exe /d /s /c "...". In versions 2.7.0 through 2.9.7, Deno's sanitization routine applied Unix-style double-quote escaping or failed to escape the Windows Command Prompt escape character (the caret ^) and chaining operators (&, |, >, <).

Because cmd.exe interprets quotes differently when parsing batch arguments, an adversary can supply crafted arguments containing unescaped delimiters, terminating the legitimate command argument and appending arbitrary shell instructions that execute under the security context of the Deno service process.

Comparison of Operating System Process Spawning Semantics

Environment Argument Passing Mechanism Vulnerability Exposure Mitigation Approach
Linux / macOS (POSIX) Null-terminated array passed directly to execve() Safe: kernel preserves argument separation even with whitespace and ampersands Native POSIX system call interface
Windows (Standard Mode) Single formatted string passed to CreateProcessW() Moderate: dependent on application-level MSVCRT argument escaping Rigorous double-quote wrapping ("...")
Windows (Shell: True) String interpreted by cmd.exe /c command parser Critical (CVE-2026-103473): Metacharacters evaluate before program launch Explicit caret escaping (^^) and disallowing shell wrappers

Remediation & Patch Deployment

  1. Upgrade Deno to v2.9.8 or Later: Deno developers must immediately update their local runtime and container base images:
    # Upgrade Deno to latest secure release
    deno upgrade
    
    # Verify installed release version
    deno --version
    # Output must indicate Deno >= 2.9.8
  2. Eliminate shell: true Invocations: Refactor codebase instances to invoke binaries directly without spawning intermediate shell interpreters. If shell functionality is required, implement strict regex whitelisting for all arguments.
  3. Audit CI/CD Container Pipelines: Ensure Windows-based build agents running Deno workflows do not expose automated build hooks to untrusted Git commit messages or branch names.