happy-dom allows for server side code to be executed by a <script> tag
- Severity:
- High
Description
Consumers of the NPM package happy-dom
Recommendation
Update the happy-dom package to the latest compatible version. Followings are version details:
- Affected version(s): < 15.10.2
- Patched version(s): 15.10.2
References
Related Issues
- Happy DOM: VM Context Escape can lead to Remote Code Execution - CVE-2025-61927
- happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript - CVE-2025-62410
- Strapi allows Server-Side Request Forgery in Webhook function - CVE-2024-52588
- CouchAuth has a Server-Side Template Injection vulnerability in its email functionality - CVE-2024-57177
- Tags:
- npm
- happy-dom
Anything's wrong? Let us know Last updated on November 06, 2024