CVE-2025-61787
Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.08%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.
- CVSS 3.1
- 8.1 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-77
- Affected
- deno/deno
- Source
- security-advisories@github.com
References
- https://github.com/denoland/deno/commit/8a0990ccd37bafd8768176ca64b906ba2da2d822Patch
- https://github.com/denoland/deno/pull/30818Issue Tracking, Patch
- https://github.com/denoland/deno/releases/tag/v2.2.15Release Notes
- https://github.com/denoland/deno/releases/tag/v2.5.3Release Notes
- https://github.com/denoland/deno/security/advisories/GHSA-m2gf-x3f6-8hq3Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.