CVE-2026-27190 is a critical command injection vulnerability (CWE-78) affecting Deno versions prior to 2.6.8, specifically within its node:child_process implementation. With a CVSS score of 9.8, this vulnerability allows unauthenticated attackers to achieve complete compromise of confidentiality, integrity, and availability with low attack complexity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.6.8CPE matchmatch criteria | cpe:2.3:a:deno:deno:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Command Injection via incomplete shell metacharacter blocklist in node:child_process (bypass of CVE-2026-27190 fix)
Mar 12, 2026Deno has a Command Injection via Incomplete shell metacharacter blocklist in node:child_process
Feb 19, 2026