
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-22864 is a command injection vulnerability in the Deno JavaScript/TypeScript/WebAssembly runtime affecting all versions before 2.5.6 on Windows. It represents an incomplete fix for a prior patch (CVE-2025-61787) that attempted to block spawning Windows batch/shell files by rejecting paths with .bat or .cmd extensions. The original check performed a case-sensitive comparison against lowercase literals, allowing bypass via alternate casing such as .BAT, .Bat, or .bAt. The vulnerability was published on January 15, 2026, and fixed in Deno 2.5.6. The CNA (GitHub) assigned a CVSS v3.1 score of 8.1 (High), while NVD assessed it at 9.8 (Critical) (Github Advisory, Deno Advisory).
The root cause is classified as CWE-77 (Improper Neutralization of Special Elements used in a Command — Command Injection). The prior security patch for CVE-2025-61787 introduced a blocklist check for .bat and .cmd file extensions when using Deno.Command to spawn processes on Windows, but the comparison was implemented as a case-sensitive string match against lowercase literals. Because Windows file extension matching is case-insensitive at the OS level, an attacker can supply a path with an uppercase or mixed-case extension (e.g., ./test.BAT) to bypass the check entirely. A public proof-of-concept demonstrates spawning ./test.BAT with user-controlled arguments (e.g., &calc.exe) to achieve arbitrary command execution (Deno Advisory, Github Advisory).
Successful exploitation allows an attacker to execute arbitrary commands on a Windows system with the privileges of the Deno process, bypassing the intended sandboxing protection. This results in high impact to confidentiality, integrity, and availability — an attacker can read sensitive data, modify files, or disrupt service operation. The vulnerability is particularly dangerous in scenarios where Deno applications accept user-controlled input that influences process spawning, such as server-side applications or build pipelines running on Windows (Deno Advisory, Github Advisory).
A public proof-of-concept exploit is available in the official GitHub security advisory, demonstrating that passing a .BAT-cased path with injected arguments (e.g., &calc.exe) to Deno.Command successfully launches arbitrary executables on Windows (Deno Advisory). The EPSS score is approximately 0.036% (11th percentile), indicating a low but non-zero probability of exploitation in the wild within 30 days (Github Advisory). No evidence of active in-the-wild exploitation or threat actor attribution has been reported. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability requires no authentication and no user interaction, though the CNA rates attack complexity as High due to the need for specific conditions (user-controlled input reaching Deno.Command on Windows).
Deno.Command or similar APIs..bat or .cmd) accessible to the Deno process, using an alternate-cased extension such as test.BAT or test.Bat to bypass the lowercase extension blocklist.&calc.exe or & malicious_payload.exe) that will be interpreted by cmd.exe when the batch file is executed.const command = new Deno.Command('./test.BAT', { args: ['&calc.exe'] });
const child = command.spawn();cmd.exe, and the injected argument is interpreted as an additional command, executing the attacker's payload with the privileges of the Deno process (Deno Advisory).cmd.exe, calc.exe, powershell.exe, or other executables) with parent process being the Deno binary; batch file executions with mixed-case extensions (.BAT, .Bat, .bAt, .CMD, etc.).Deno.Command invocations referencing .BAT or .CMD files with non-lowercase extensions; Windows Event Logs (Event ID 4688) recording process creation by the Deno process with unusual child processes.*.BAT, *.CMD) in directories accessible to the Deno process; newly created or modified scripts in Deno application directories.The primary remediation is to upgrade Deno to version 2.5.6 or later, which re-implements the batch/shell file spawning restriction using case-insensitive extension comparison (Deno Release). No official configuration-based workaround is provided; however, as an interim measure, operators should restrict execution of untrusted Deno applications on Windows, avoid passing user-controlled input to Deno.Command, and implement network-level controls to limit exposure of vulnerable Deno services (Github Advisory). Monitoring for suspicious process spawning patterns (especially batch files with non-lowercase extensions) is also recommended until patching is complete.
The vulnerability was reported by security researcher SharokhAtaie and published by Deno maintainer bartlomieju on January 15, 2026 (Deno Advisory). Security news outlet SecurityOnline.info covered the vulnerability alongside a related Deno flaw (CVE-2026-22863), highlighting the risk to secrets and code execution on Windows. Social media discussion was observed on Bluesky, with the infosec community noting the incomplete-fix nature of the vulnerability. The CISA weekly vulnerability bulletin for the week of January 12, 2026 referenced the issue, indicating broader government awareness.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."