CVE-2025-61787
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, `CreateProcess() always implicitly spawns cmd.exe` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line.
This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
HIGH · CVSS 8.1
EPSS 0.0017
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules8
YARA rules0