PT-2025-41212 · Deno · Deno

R4356Th

·

Published

2025-10-08

·

Updated

2026-04-14

·

CVE-2025-61787

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Deno versions prior to 2.5.3 and 2.2.15
Description Deno, a JavaScript, TypeScript, and WebAssembly runtime, is susceptible to Command Line Injection attacks on Windows operating systems when batch files are executed. The Windows operating system implicitly uses cmd.exe when executing batch files, even if not explicitly specified, creating a pathway for attackers to inject malicious commands through user input. Approximately 654 systems are estimated to be affected, and over 1,300 services are found annually. The vulnerability resides in the way Deno handles the CreateProcess() function when executing batch files on Windows. The CreateProcess() function is used to create a new process, and in the case of batch files, it automatically invokes cmd.exe. This behavior allows attackers to inject commands into the batch file, which are then executed by cmd.exe.
Recommendations Update Deno to version 2.5.3 or 2.2.15 to resolve this issue.

Exploit

Fix

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2025-61787
GHSA-M2GF-X3F6-8HQ3
JLSEC-2026-113

Affected Products

Deno