cbcvebase.
CVE-2025-61787
published 2025-10-08

CVE-2025-61787: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when…

PriorityP354high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
2.08%
80.7th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.

Affected

6 ranges
VendorProductVersion rangeFixed in
denodeno<= 2.2.15—
denodeno>= 0 < 2.5.62.5.6
denodeno>= 0 < 2.5.22.5.2
denodeno>= 2.3.0 < 2.5.32.5.3
denolanddeno< 2.2.152.2.15
denolanddeno——

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.