Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/happy-dom — 5 CVEs · VulnScope
pkg:npm/
happy-dom
5 total CVEs
HIGH
2
✅ Check your installed version
Check
All known vulnerabilities
HIGH
8.8
CVE-2026-33943
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
>= 15.10.0, < 20.8.8
HIGH
7.5
CVE-2026-34226
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
from 0, < 20.8.9
—
CVE-2025-62410
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
>= 19.0.0, < 20.0.2
—
CVE-2025-61927
Happy DOM: VM Context Escape can lead to Remote Code Execution
from 0, < 20.0.0
—
happy-dom allows for server side code to be executed by a <script> tag
from 0, < 15.10.2
CVE-2024-51757