No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qpm2-6cq5-7pq5 | happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript |
Mon, 20 Oct 2025 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Capricorn86
Capricorn86 happy-dom |
|
| Vendors & Products |
Capricorn86
Capricorn86 happy-dom |
Thu, 16 Oct 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 15 Oct 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Oct 2025 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom. The untrusted script and the rest of the application still run in the same Isolate/process, so attackers can deploy prototype pollution payloads to hijack important references like "process" in the example below, or to hijack control flow via flipping checks of undefined property. This vulnerability is due to an incomplete fix for CVE-2025-61927. The vulnerability is fixed in 20.0.2. | |
| Title | --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-15T18:16:44.558Z
Reserved: 2025-10-13T16:26:12.178Z
Link: CVE-2025-62410
Updated: 2025-10-15T18:16:01.640Z
Status : Deferred
Published: 2025-10-15T18:15:40.567
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-62410
OpenCVE Enrichment
Updated: 2025-10-20T13:25:23Z
Github GHSA