Description
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to ensure that the inputs to Function are not attacker-controlled.
Recommendation
Update the dom-iterator package to the latest compatible version. Followings are version details:
- Affected version(s): <= 1.0.0
- Patched version(s): 1.0.1
References
Related Issues
- Trix Editor Arbitrary Code Execution Vulnerability - CVE-2024-34341
- JSONPath Plus Remote Code Execution (RCE) Vulnerability - CVE-2024-21534
- Happy DOM: VM Context Escape can lead to Remote Code Execution - CVE-2025-61927
- PrismJS DOM Clobbering vulnerability - CVE-2024-53382
You might also like:
- Tags:
- npm
- dom-iterator
Anything's wrong? Let us know Last updated on January 14, 2025


