PT-2025-42391 · Happy-Dom · Happy-Dom
Published
2025-10-15
·
Updated
2025-10-16
·
CVE-2025-62410
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
happy-dom versions prior to 20.0.2
Description
The software does not sufficiently isolate untrusted JavaScript, even when using the
--disallow-code-generation-from-strings flag. The untrusted script and the main application share the same Isolate/process, allowing attackers to use prototype pollution to hijack references, such as process, or manipulate control flow by altering checks for undefined properties. This is an incomplete fix for a previously identified issue.Recommendations
Update to version 20.0.2 or later.
Exploit
Fix
RCE
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Happy-Dom