CRITICALnpm
GHSA-37j7-fg3j-429f· CVE-2025-61927Happy DOM: VM Context Escape can lead to Remote Code Execution
Modified: 10/13/2025
package
pkg:npm/happy-dom
Happy DOM: VM Context Escape can lead to Remote Code Execution
Modified: 10/13/2025
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
Modified: 3/30/2026
happy-dom allows for server side code to be executed by a <script> tag
Modified: 11/6/2024
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
Modified: 11/27/2025
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
Modified: 3/29/2026