
Deno fixes High-severity command injection in node:child_process when using shell:true (CVE-2026-32260)
Deno published a High-severity command injection flaw in its node:child_process polyfill that can bypass Deno permissions when shell:true is used with attacker-controlled arguments.
NewsRuntime SecuritySupply Chain
13 Mar 2026