External risk intelligence

Deno Windows Command Injection via Node Child Process.

CVE advisorySeverity: CRITICAL (CVSS 9.2)

CVE-2026-103473

The vulnerability affects the node:child_process module in Deno on Windows. While classified as network-accessible, exploitation requires the application to specifically use this module to process untrusted input with the shell option. Exposure is therefore contingent on application-specific implementation rather than being inherent to all internet-facing Deno services.

OS Command Injection

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability has been identified in Deno on Windows, specifically impacting the `node:child_process` module. This issue allows attackers to execute arbitrary commands by exploiting how shell arguments are handled, potentially leading to unauthorized command execution with the privileges of the Deno process.

  • Deno on Windows allows command injection via child process.
  • It enables arbitrary command execution with Deno process privileges.
  • Confirm relevance and exposure for affected Deno deployments.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted, untrusted arguments to a Deno application running on Windows that utilizes the `node:child_process` module with the `shell` option. This could allow the attacker to execute arbitrary operating system commands with the same privileges as the Deno process.

  • Requires attacker to control arguments.
  • Vulnerability triggered by `node:child_process` shell.
  • Allows arbitrary OS command execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow an attacker to execute arbitrary operating system commands with the privileges of the Deno process when the application improperly handles untrusted input passed as shell arguments to the `node:child_process` module on Windows. This could impact system integrity and the execution of Deno applications.

  • System commands could be executed.
  • Untrusted arguments may be passed to `node:child_process`.
  • Arbitrary code execution with Deno privileges.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Deno runtime's `node:child_process` module on Windows is susceptible to command injection when handling untrusted arguments with the shell option. This vulnerability could allow arbitrary command execution with Deno process privileges. Responsibility for addressing this likely falls to the Deno application owners and the platform or infrastructure teams managing the Deno runtime. The initial step involves identifying all Deno deployments on Windows, assessing their exposure and criticality, confirming ownership, and then planning remediation, potentially involving vendor coordination or temporary risk reduction measures.

  • Deno application owners should manage remediation.
  • Verify Deno Windows deployments and exposure.
  • Plan risk-based remediation with vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Deno runtime and the node:child_process module?

Deno is a modern, secure runtime for JavaScript and TypeScript. The node:child_process module is a specific compatibility layer within Deno that allows developers to run system-level commands, mimicking the functionality found in Node.js environments.

What does command injection mean in the context of CVE-2026-103473?

This vulnerability, classified as CWE-78, occurs when an application improperly filters input before passing it to a system shell. Because Deno incorrectly handles how shell arguments are escaped on Windows, an attacker can append their own malicious commands, forcing the system to execute unauthorized tasks with the permissions of the Deno application.

How is this command injection triggered?

The vulnerability is triggered only when a Deno application specifically uses the node:child_process module with the shell option enabled to process untrusted input. If an application does not use this module, uses it without the shell option, or only processes trusted, hard-coded arguments, it is not susceptible to this specific flaw.

Do I need to worry about this if my Deno app is on the internet?

Halo Surface Signal indicates that while the vulnerability is network-accessible, exposure is not automatic. It depends on whether your application logic accepts external user input and passes it through the affected child_process module. Even if your service is internet-facing, it is only at risk if the code path processes untrusted data in that specific way.

How should I respond to this Deno vulnerability?

First, inventory your Deno environment to confirm if you are running versions 2.7.0 through 2.9.7 on Windows. If affected, audit your application code to identify any use of node:child_process where the shell option is set. Prioritize updating the Deno runtime version and evaluate if your application can be refactored to avoid passing untrusted input to shell-based processes.

References