OS Command Injection in Deno - CVE-2026-32260
Published: April 23, 2026
Deno
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary OS commands.
The vulnerability exists due to improper neutralization of special elements used in an OS command in the node:child_process polyfill when handling user-controlled arguments passed to spawn or spawnSync with shell: true. A remote attacker can supply crafted arguments containing shell metacharacters to execute arbitrary OS commands.
Exploitation bypasses Deno's permission system and requires the application to invoke the vulnerable functionality with shell: true.