
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32260 is a command injection vulnerability in Deno's node:child_process polyfill that bypasses the prior fix for CVE-2026-27190. It affects Deno versions 2.7.0 and 2.7.1, and was disclosed on March 12, 2026, with a patch released in version 2.7.2. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) per the official GitHub Security Advisory, though some sources estimate it as high as 9.8 (Github Advisory, Deno Advisory).
The root cause is a priority bug (CWE-78) in the two-stage argument sanitization logic within transformDenoShellCommand (ext/node/polyfills/internal/child_process.ts). The attack chain proceeds as follows: escapeShellArg initially wraps arguments in single quotes (safe), but op_node_parse_shell_args strips those single-quote delimiters during tokenization, exposing the raw argument. The re-quoting stage then detects a $VAR pattern and wraps the argument in double quotes instead of single quotes — and since POSIX sh does not suppress backtick command substitution inside double quotes, an attacker-controlled backtick payload executes via /bin/sh. Exploitation requires that the attacker control arguments passed to spawn or spawnSync with shell: true, and that the Deno process runs with --allow-run (Deno Advisory, Github Advisory).
Successful exploitation allows an attacker to execute arbitrary OS commands at the process level of the Deno runtime, effectively bypassing Deno's permission sandbox. This results in full confidentiality, integrity, and availability compromise of the host system — including unauthorized data access, file system modification, and potential denial of service. Because injected commands run outside Deno's permission model, the attacker can perform actions that would otherwise be restricted by Deno's security architecture (Deno Advisory).
No confirmed in-the-wild exploitation has been observed, and no functional public exploit code is available — the GitHub Security Advisory provides only vulnerability analysis and mitigation guidance without a concrete payload or reproduction steps (Deno Advisory). The EPSS score is approximately 0.119% (30th percentile), indicating a relatively low near-term exploitation probability (Github Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this CVE (detection ID 5009181) (Feedly).
node:child_process spawn or spawnSync with shell: true and accept user-controlled input as arguments.$VAR pattern combined with a backtick command substitution payload, e.g., $VAR\malicious_command`— the$VAR` pattern triggers double-quote wrapping in the re-quoting stage.spawnSync/spawn with shell: true.transformDenoShellCommand function wraps the argument in double quotes due to the $VAR detection, and /bin/sh evaluates the backtick expression, executing the injected OS command outside Deno's permission sandbox (Deno Advisory, Github Advisory)./bin/sh, bash, curl, wget, python) with unusual arguments or parent-child relationships.`), $VAR patterns, or shell metacharacters being passed to spawn/spawnSync calls.Upgrade Deno to version 2.7.2 or later, which contains the fix for this vulnerability (Deno Advisory). For systems that cannot upgrade immediately, avoid passing user-controlled input as arguments to spawn or spawnSync with shell: true; use shell: false (the default) instead. Additionally, validate and sanitize all arguments before passing them to child process APIs, and audit application code for any use of shell: true with externally influenced input (Github Advisory).
The advisory was published by Deno maintainer bartlomieju on March 12, 2026, and credited researcher rtvkiz for the discovery (Deno Advisory). The vulnerability was noted across several vulnerability tracking platforms and Bluesky security community accounts shortly after disclosure, reflecting routine community awareness activity with no exceptional controversy or widespread media coverage observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."