CVE-2026-27190

CRITICAL WAF: High
CVSS 9.8 Published: 2026-02-20
CWE-78

Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.6.8, a command injection vulnerability exists in Deno's node:child_process implementation. This vulnerability is fixed in 2.6.8.

WAF Coverage Analysis

OS Command Injection High WAF Coverage

OWASP: A03:2021 Injection

932xxx - Remote Code Execution

Affected Software

VendorProductVersion
denodenoup to 2.6.8

References

Back to CVE Database