CVE-2026-103473

LOWCVSS 9.2 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft

    🚨 DENO CVE-2026-103473 — CVSS 8.1 Command injection in node:child_process on Windows. escapeShellArg() applies POSIX rules to cmd.exe → metacharacters not neutralized. Arbitrary commands run as the Deno process. 🔗 https://threataft.com/articles/deno-cve-2026-103473-command-injection-windows?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #ThreatIntel #Deno

    0000041
    44 followersView on X

Explore more