Deno versions up to 2.5.1 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.
In Windows, CreateProcess() always implicitly spawns cmd.exe if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows as demonstrated by the two proves-of-concept below.
Using node:child_process (with the env and run permissions):
const { spawn } = require('node:child_process');
const child = spawn('./test.bat', ['&calc.exe']);
Using Deno.Command.spawn() (with the run permission):
const command = new Deno.Command('./test.bat', {
args: ['&calc.exe'],
});
const child = command.spawn();
Both of these scripts result in opening calc.exe on Windows, thus allowing a Command Line Injection attack when user-provided arguments are passed if the script being executed by the child process is a batch script.
{
"license": "CC-BY-4.0",
"sources": [
{
"database_specific": {
"status": "Analyzed"
},
"id": "CVE-2025-61787",
"published": "2025-10-08T02:15:41.897Z",
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-61787",
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61787",
"modified": "2026-06-17T09:50:54.167Z",
"imported": "2026-07-17T21:10:26.814Z"
},
{
"id": "GHSA-m2gf-x3f6-8hq3",
"published": "2025-10-08T18:16:24Z",
"url": "https://api.github.com/advisories/GHSA-m2gf-x3f6-8hq3",
"html_url": "https://github.com/advisories/GHSA-m2gf-x3f6-8hq3",
"modified": "2025-10-08T18:16:25Z",
"imported": "2026-07-17T21:10:26.973Z"
},
{
"id": "EUVD-2025-33179",
"published": "2025-10-08T00:59:17Z",
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-33179",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-33179",
"modified": "2025-10-08T18:51:09Z",
"imported": "2026-07-17T21:10:36.871Z"
}
]
}