Retour à la veille
CVE-2026-103473
Score CVSS
8.1
HIGH
Description détaillée
Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Références et Patchs
https://github.com/denoland/denohttps://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1339https://github.com/denoland/deno/blob/0c071246a412575e07423263404a5d13e7ed6aa2/ext/node/polyfills/internal/child_process.ts#L1499https://github.com/denoland/deno/pull/36772https://www.vulncheck.com/advisories/deno-2.7.0-through-2.9.7-command-injection-via-node-child-process
Dernières Vulnérabilités
CVE-2026-97291
Contributor PHP Object Injection in Schema & Structured Data for WP & AMP <= 1.66 versions.
VOIR DÉTAILS
CVE-2026-97290
Unauthenticated Cross Site Scripting (XSS) in Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.36 versions.
VOIR DÉTAILS
CVE-2026-97265
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Crocoblock. Jetimpex Inc. JetEngine allows Stored XSS. This issue affects JetEngine: from n/a through 3.8.15.3.
VOIR DÉTAILS
