A vulnerability classified as critical has been found in denoland deno up to 2.7.1. Affected by this issue is the function child_process of the file ext/node/polyfills/internal/child_process.ts of the component Double Quote Handler. Performing a manipulation results in os command injection.

This vulnerability is cataloged as CVE-2026-32260. It is possible to initiate the attack remotely. There is no exploit available.

It is recommended to upgrade the affected component.