<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T06:42:22.943162+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-254456</id>
    <title>EUVD-2026-254456</title>
    <updated>2026-10-06T06:42:22.950546+00:00</updated>
    <content>EUVD-2026-254456</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-254456"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-61787</id>
    <title>fkie_cve-2025-61787</title>
    <updated>2026-10-06T06:42:22.950613+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Deno is a JavaScript, TypeScript, and WebAssembly runtime. Versions prior to 2.5.3 and 2.2.15 are vulnerable to Command Line Injection attacks on Windows when batch files are executed. In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows. Versions 2.5.3 and 2.2.15 fix the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-61787"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m2gf-x3f6-8hq3</id>
    <title>GHSA-m2gf-x3f6-8hq3 — Deno is Vulnerable to Command Injection on Windows During Batch File Execution</title>
    <updated>2026-10-06T06:42:22.950646+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> crates.io: deno</p>
<p>### Summary
Deno versions up to 2.5.1 are vulnerable to Command Line Injection attacks on Windows when batch files are executed.</p>
<p>### Details
In Windows, ``CreateProcess()`` always implicitly spawns ``cmd.exe`` if a batch file (.bat, .cmd, etc.) is being executed even if the application does not specify it via the command line. This makes Deno vulnerable to a command injection attack on Windows as demonstrated by the two proves-of-concept below.</p>
<p>### PoC
Using `node:child_process` (with the `env` and `run` permissions):
```JS
const { spawn } = require('node:child_process');
const child = spawn('./test.bat', ['&amp;calc.exe']);
```
Using `Deno.Command.spawn()` (with the `run` permission):
```JS
const command = new Deno.Command('./test.bat', {
  args: ['&amp;calc.exe'],
});
const child = command.spawn();
```</p>
<p>### Impact
Both of these scripts result in opening calc.exe on Windows, thus allowing a Command Line Injection attack when user-provided arguments are passed if the script being executed by the child process is a batch script.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m2gf-x3f6-8hq3"/>
  </entry>
</feed>
