CVE-2026-22864
published 2026-01-15CVE-2026-22864: Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.68%
51.0th percentile
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.). This vulnerability is fixed in 2.5.6.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| deno | deno | < 2.5.6 | 2.5.6 |
| deno | deno | >= 0 < 2.5.6 | 2.5.6 |
| denoland | deno | < 2.5.6 | 2.5.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa8.1HIGH
osv8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
osv·2026-01-16·CVSS 8.1
CVE-2026-22864 [HIGH] Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
### Summary
A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).
### POC
```javascript
const command = new Deno.Command('./test.BAT', {
args: ['&calc.exe'],
});
const child = command.spawn();
```
This causes `calc.exe` to be launched; see the attached screenshot for evidence.
**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**
**Bypass of the patched vulnerability:**
### Impact
The s
GHSA
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
ghsa·2026-01-16·CVSS 8.1
CVE-2026-22864 [HIGH] CWE-77 Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass
### Summary
A prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).
### POC
```javascript
const command = new Deno.Command('./test.BAT', {
args: ['&calc.exe'],
});
const child = command.spawn();
```
This causes `calc.exe` to be launched; see the attached screenshot for evidence.
**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**
**Bypass of the patched vulnerability:**
### Impact
The s
No detection rules found.
No public exploits indexed.
2026-01-15
Published