CVE-2026-27190Disclosure(deno / deno)

LOWCVSS 9.8 · CRITICAL

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • deno

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
deno

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-20: 2Technical Details · 2026-02-20: 202-20
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-27190 Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This … https://www.cve.org/CVERecord?id=CVE-2026-27190

    Post summary

    The text announces a command injection flaw in Deno versions before 2.6.8 and points to the CVE record for details.

    0000093
    56.4K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE ID:** CVE-2026-27190 **Description:** This vulnerability pertains to Deno versions prior to 2.6.8, where a command injection flaw exists within the `node:child_process` implementation. The flaw allows an attacker to execute arbitrary commands on the host system by exploiting the way Deno handles subprocess execution, particularly when untrusted input is passed to command execution functions. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution https://cvetodo.com/cve/CVE-2026-27190

    Post summary

    The post announces CVE-2026-27190 as a command injection flaw in older Deno versions that enables arbitrary host execution; no PoC, exploit, patch, or active exploitation is mentioned.

    0000024
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appdenodeno---

Explore more