PT-2025-42391 · Happy-Dom · Happy-Dom

Published

2025-10-15

·

Updated

2025-10-16

·

CVE-2025-62410

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions happy-dom versions prior to 20.0.2
Description The software does not sufficiently isolate untrusted JavaScript, even when using the --disallow-code-generation-from-strings flag. The untrusted script and the main application share the same Isolate/process, allowing attackers to use prototype pollution to hijack references, such as process, or manipulate control flow by altering checks for undefined properties. This is an incomplete fix for a previously identified issue.
Recommendations Update to version 20.0.2 or later.

Exploit

Fix

RCE

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62410
GHSA-QPM2-6CQ5-7PQ5

Affected Products

Happy-Dom