CVE-2025-61787
published 2025-10-08CVE-2025-61787: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when…
PriorityP354high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.08%
80.7th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | <= 2.2.15 | — |
| deno | deno | >= 0 < 2.5.6 | 2.5.6 |
| deno | deno | >= 0 < 2.5.2 | 2.5.2 |
| deno | deno | >= 2.3.0 < 2.5.3 | 2.5.3 |
| denoland | deno | < 2.2.15 | 2.2.15 |
| denoland | deno | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
osv·2026-01-16·CVSS 8.1
CVE-2026-22864 [HIGH] Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
### Summary
A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).
### POC
```javascript
const command = new Deno.Command('./test.BAT', {
args: ['&calc.exe'],
});
const child = command.spawn();
```
This causes `calc.exe` to be launched; see the attached screenshot for evidence.
**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**
**Bypass of the patched vulnerability:**
### Impact
The s
GHSA
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
ghsa·2026-01-16·CVSS 8.1
CVE-2026-22864 [HIGH] CWE-77 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
### Summary
A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).
### POC
```javascript
const command = new Deno.Command('./test.BAT', {
args: ['&calc.exe'],
});
const child = command.spawn();
```
This causes `calc.exe` to be launched; see the attached screenshot for evidence.
**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**
**Bypass of the patched vulnerability:**
### Impact
The s
GHSA
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
ghsa·2025-10-08
CVE-2025-61787 [HIGH] CWE-77 Deno is Vulnerable to Command Injection on Windows During Batch File Execution
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
### Summary
Deno versions up to 2.5.1 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.
### Details
In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows as demonstrated by the two proves-of-concept below.
### PoC
Using `node:child_process` (with the `env` and `run` permissions):
```JS
const { spawn } = require('node:child_process');
const child = spawn('./test.bat', ['&calc.exe']);
```
Using `Deno.Command.spawn()` (with the `run` permission):
```JS
const command = new D
OSV
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
osv·2025-10-08
CVE-2025-61787 [HIGH] Deno is Vulnerable to Command Injection on Windows During Batch File Execution
Deno is Vulnerable to Command Injection on Windows During Batch File Execution
### Summary
Deno versions up to 2.5.1 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.
### Details
In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows as demonstrated by the two proves-of-concept below.
### PoC
Using `node:child_process` (with the `env` and `run` permissions):
```JS
const { spawn } = require('node:child_process');
const child = spawn('./test.bat', ['&calc.exe']);
```
Using `Deno.Command.spawn()` (with the `run` permission):
```JS
const command = new D
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/denoland/deno/commit/8a0990ccd37bafd8768176ca64b906ba2da2d822https://github.com/denoland/deno/pull/30818https://github.com/denoland/deno/releases/tag/v2.2.15https://github.com/denoland/deno/releases/tag/v2.5.3https://github.com/denoland/deno/security/advisories/GHSA-m2gf-x3f6-8hq3
2025-10-08
Published