CVE-2026-22864
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows b
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, etc.).
This vulnerability is fixed in 2.5.6.
HIGH · CVSS 8.1
EPSS 0.00036
Act now
- Public exploit or PoC is available
- CVSS base score ≥ 7.0
Sigma rules1
YARA rules0