A high-severity vulnerability, tracked as CVE-2025-61787, was identified in Deno, a runtime for JavaScript, TypeScript, and WebAssembly. The flaw specifically affects Windows systems and allows for command injection when batch files are executed. The vulnerability arises because, on Windows, the CreateProcess() function implicitly invokes cmd.exe when executing batch files, even if the application does not explicitly specify it. This behavior enables attackers to inject arbitrary commands if they can influence the batch file execution process. Deno versions prior to 2.5.3 and 2.2.15 are confirmed to be vulnerable to this issue. The vulnerability is remotely exploitable, increasing the risk for systems running affected Deno versions on Windows. Security advisories highlight that the issue is fixed in Deno versions 2.5.3 and 2.2.15, and users are urged to upgrade to these or later versions to mitigate the risk. The vulnerability was disclosed publicly in early October 2025, and its high CVSS score of 8.1 reflects the significant risk it poses. The flaw could potentially allow attackers to execute arbitrary commands with the privileges of the Deno process, leading to system compromise or further lateral movement. The vulnerability does not appear to affect non-Windows platforms, as the underlying issue is tied to Windows-specific process creation behavior. No reports of active exploitation have been confirmed at the time of disclosure, but the remote exploitability and ease of triggering the flaw make it a priority for patching. The Deno development team responded promptly by releasing patched versions and providing detailed advisories to the community. Organizations using Deno in production on Windows are strongly advised to audit their deployments and ensure all instances are updated. Security teams should also review application logic to ensure that untrusted input cannot influence batch file execution. The vulnerability underscores the importance of understanding platform-specific behaviors in cross-platform runtimes. Deno's maintainers have also recommended additional security best practices for users who cannot immediately upgrade. The disclosure has prompted broader discussions about secure process execution and command injection risks in modern runtimes.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
CVE-2025-61787 was publicly disclosed as a high-severity remotely exploitable command injection flaw affecting Deno on Windows during batch file execution. Public reporting identified affected versions prior to 2.5.3 and 2.2.15 and recommended updating to the fixed releases.
Deno addressed a command injection vulnerability on Windows related to executing .bat and .cmd files, caused by CreateProcess() implicitly invoking cmd.exe. The fix was released in Deno versions 2.5.3 and 2.2.15, with prior versions affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.