CVE-2026-32260: 
Rust vulnerability analysis and mitigation

Overview

CVE-2026-32260 is a command injection vulnerability in Deno's node:child_process polyfill that bypasses the prior fix for CVE-2026-27190. It affects Deno versions 2.7.0 and 2.7.1, and was disclosed on March 12, 2026, with a patch released in version 2.7.2. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) per the official GitHub Security Advisory, though some sources estimate it as high as 9.8 (Github Advisory, Deno Advisory).

Technical details

The root cause is a priority bug (CWE-78) in the two-stage argument sanitization logic within transformDenoShellCommand (ext/node/polyfills/internal/child_process.ts). The attack chain proceeds as follows: escapeShellArg initially wraps arguments in single quotes (safe), but op_node_parse_shell_args strips those single-quote delimiters during tokenization, exposing the raw argument. The re-quoting stage then detects a $VAR pattern and wraps the argument in double quotes instead of single quotes — and since POSIX sh does not suppress backtick command substitution inside double quotes, an attacker-controlled backtick payload executes via /bin/sh. Exploitation requires that the attacker control arguments passed to spawn or spawnSync with shell: true, and that the Deno process runs with --allow-run (Deno Advisory, Github Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary OS commands at the process level of the Deno runtime, effectively bypassing Deno's permission sandbox. This results in full confidentiality, integrity, and availability compromise of the host system — including unauthorized data access, file system modification, and potential denial of service. Because injected commands run outside Deno's permission model, the attacker can perform actions that would otherwise be restricted by Deno's security architecture (Deno Advisory).

Exploitability

No confirmed in-the-wild exploitation has been observed, and no functional public exploit code is available — the GitHub Security Advisory provides only vulnerability analysis and mitigation guidance without a concrete payload or reproduction steps (Deno Advisory). The EPSS score is approximately 0.119% (30th percentile), indicating a relatively low near-term exploitation probability (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this CVE (detection ID 5009181) (Feedly).

Exploitation steps

  1. Identify vulnerable targets: Locate applications running Deno v2.7.0 or v2.7.1 that use node:child_process spawn or spawnSync with shell: true and accept user-controlled input as arguments.
  2. Craft a malicious argument: Prepare an argument containing a $VAR pattern combined with a backtick command substitution payload, e.g., $VAR\malicious_command`— the$VAR` pattern triggers double-quote wrapping in the re-quoting stage.
  3. Trigger the sanitization bypass: Submit the crafted argument through the application's input vector (e.g., an API parameter, form field, or CLI argument) so it is passed to spawnSync/spawn with shell: true.
  4. Achieve command execution: The transformDenoShellCommand function wraps the argument in double quotes due to the $VAR detection, and /bin/sh evaluates the backtick expression, executing the injected OS command outside Deno's permission sandbox (Deno Advisory, Github Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Deno runtime (e.g., /bin/sh, bash, curl, wget, python) with unusual arguments or parent-child relationships.
  • Logs: Application logs showing user-supplied input containing backtick characters (`), $VAR patterns, or shell metacharacters being passed to spawn/spawnSync calls.
  • Network: Unexpected outbound network connections from the Deno process to external IPs, particularly on non-standard ports, which may indicate reverse shell or data exfiltration activity.
  • File System: New or modified files created by the Deno process in unexpected directories, or the presence of scripts/binaries dropped by the injected command.

Mitigation and workarounds

Upgrade Deno to version 2.7.2 or later, which contains the fix for this vulnerability (Deno Advisory). For systems that cannot upgrade immediately, avoid passing user-controlled input as arguments to spawn or spawnSync with shell: true; use shell: false (the default) instead. Additionally, validate and sanitize all arguments before passing them to child process APIs, and audit application code for any use of shell: true with externally influenced input (Github Advisory).

Community reactions

The advisory was published by Deno maintainer bartlomieju on March 12, 2026, and credited researcher rtvkiz for the discovery (Deno Advisory). The vulnerability was noted across several vulnerability tracking platforms and Bluesky security community accounts shortly after disclosure, reflecting routine community awareness activity with no exceptional controversy or widespread media coverage observed.

Additional resources


Source: This report was generated using AI

Related Rust vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-6w6g-hm98-mhgmHIGH8.7
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-5j98-2g5x-46v6HIGH7.5
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-cjcg-cxmh-9wcrHIGH7.5
  • Rust logoRust
  • praxis-proxy
NoYesOct 02, 2026
GHSA-6f2x-v7q7-m7m5MEDIUM6.9
  • Rust logoRust
  • hickory-resolver
NoYesOct 05, 2026
GHSA-6g2r-675j-hx59LOW2.3
  • Rust logoRust
  • xxhash-rust
NoYesOct 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management