天下漏洞,尽知其名
HIGH

CVE-2026-103473 Deno node:child_process 命令注入漏洞

影响攻击者可注入并执行任意系统命令

AI 研判

Deno 在 Windows 平台上的 node:child_process 模块存在命令注入漏洞。当使用 shell 选项时,参数按错误的 shell 类型进行转义,导致不可信参数可注入操作系统命令。攻击者借此可以 Deno 进程权限执行任意命令。

影响范围

Deno

Deno 2.7.0 至 2.9.7 版本,且运行于 Windows 平台。

漏洞详情

漏洞类型为命令注入(CWE-78)。成因是 node:child_process 在启用 shell 选项时,对参数的转义规则与实际使用的 shell 类型不匹配,导致转义失效。攻击者只需向使用 shell 选项的调用传入包含 shell 元字符的不可信参数,即可拼接并执行任意系统命令。

利用条件与风险

利用前提是应用在 Windows 上使用 node:child_process 的 shell 选项并传入外部可控参数。实战中若参数来自用户输入,可导致远程命令执行,风险较高。

修复建议

建议升级 Deno 至 2.9.7 之后的修复版本;暂无公开信息说明具体修复版本号。临时缓解措施为避免在 Windows 上对不可信输入使用 shell 选项,或对参数进行严格校验与白名单过滤。

原始情报

Deno versions 2.7.0 through 2.9.7 on Windows contain a command injection vulnerability in node:child_process where shell arguments are escaped for the wrong shell type. Attackers can inject OS commands by passing untrusted arguments with the shell option, allowing arbitrary command execution with Deno process privileges.