VDB
Sign up
CRITICAL

GHSA-96g7-g7g9-jxw8

happy-dom allows for server side code to be executed by a <script> tag

Quick fix

GHSA-96g7-g7g9-jxw8 — happy-dom: upgrade to the fixed version with the command below.

npm install happy-dom@15.10.2

Details

### Impact Consumers of the NPM package `happy-dom`

### Patches The security vulnerability has been patched in v15.10.2

### Workarounds No easy workarounds to my knowledge

### References [#1585](https://github.com/capricorn86/happy-dom/issues/1585)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/happy-dom
Introduced in: 0Fixed in: 15.10.2
Fixnpm install happy-dom@15.10.2

References