Description
No description available.
Recommendation
Update the happy-dom package to the latest compatible version. Followings are version details:
- Affected version(s): < 20.0.0
- Patched version(s): 20.0.0
References
Related Issues
- happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript - CVE-2025-62410
- javascript-deobfuscator crafted payload can lead to code execution - CVE-2024-36120
- DocsGPT Allows Remote Code Execution - CVE-2025-0868
- Lobe Chat Desktop vulnerable to Remote Code Execution via XSS in Chat Messages - CVE-2025-59417
You might also like:
- Tags:
- npm
- happy-dom
Anything's wrong? Let us know Last updated on October 13, 2025


