{"id":"GHSA-m3c4-prhw-mrx6","summary":"Deno has an incomplete fix for command-injection prevention on Windows — case-insensitive extension bypass","details":"### Summary\nA prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched `.bat` or `.cmd`. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example `.BAT, .Bat`, etc.).\n\n### POC\n```javascript\nconst command = new Deno.Command('./test.BAT', {\n  args: ['&calc.exe'],\n});\nconst child = command.spawn();\n```\nThis causes `calc.exe` to be launched; see the attached screenshot for evidence.\n\n**Patched in `CVE-2025-61787` — prevents execution of `.bat` and `.cmd` files:**\n![photo_2025-10-10 02 27 23](https://github.com/user-attachments/assets/43df25e2-e2e1-48aa-8060-cb0a22637f1f)\n\n**Bypass of the patched vulnerability:**\n![photo_2025-10-10 02 27 25](https://github.com/user-attachments/assets/2be1afb4-84a1-4883-8e18-6a174fdd3615)\n\n\n### Impact\nThe script launches calc.exe on Windows, demonstrating that passing user-controlled arguments to a spawned batch script can result in command-line injection.\n\n### Mitigation\n\nUsers should update to Deno v2.5.6 or newer.","aliases":["CVE-2026-22864"],"modified":"2026-02-03T03:17:23.271119Z","published":"2026-01-16T15:49:38Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-01-16T15:49:38Z","nvd_published_at":"2026-01-15T23:15:51Z","cwe_ids":["CWE-77"]},"references":[{"type":"WEB","url":"https://github.com/denoland/deno/security/advisories/GHSA-m3c4-prhw-mrx6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22864"},{"type":"PACKAGE","url":"https://github.com/denoland/deno"},{"type":"WEB","url":"https://github.com/denoland/deno/releases/tag/v2.5.6"}],"affected":[{"package":{"name":"deno","ecosystem":"crates.io","purl":"pkg:cargo/deno"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.5.6"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/01/GHSA-m3c4-prhw-mrx6/GHSA-m3c4-prhw-mrx6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}