cvedb.io
CVE-2026-22864
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2026-01-15T23:15:51.937 · Last modified 2026-06-17T10:20:31.700

Summary

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Before 2.5.6, a prior patch aimed to block spawning Windows batch/shell files by returning an error when a spawned path’s extension matched .bat or .cmd. That check performs a case-sensitive comparison against lowercase literals and therefore can be bypassed when the extension uses alternate casing (for example .BAT, .Bat, etc.). This vulnerability is fixed in 2.5.6.

Affected products

deno — deno

Does this affect you?

Add your gear to cvedb and we'll alert you only when deno ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.