The Lab · 2026-03-27 11:27:29 · GitHub Issues
A critical remote code execution (RCE) vulnerability has been disclosed in the popular JavaScript testing library happy-dom. The flaw, tracked as CVE-2026-33943, resides in the library's `ECMAScriptModuleCompiler` component. It allows an attacker to inject and execute arbitrary JavaScript code by manipulating unsanitiz...
The Lab · 2026-03-27 23:27:21 · GitHub Issues
A critical security vulnerability in the popular Node.js module `happy-dom` exposes thousands of projects to potential remote code execution (RCE). The flaw, tracked as CVE-2026-33943, resides in the library's `ECMAScriptModuleCompiler`. It allows an attacker to inject arbitrary JavaScript expressions directly into `ex...
The Lab · 2026-03-29 20:26:56 · GitHub Issues
A severe code injection vulnerability in the popular `happy-dom` Node.js library has been disclosed, enabling attackers to achieve Remote Code Execution (RCE). The flaw, tracked as CVE-2026-33943, resides within the library's `ECMAScriptModuleCompiler` component. It allows an attacker to inject and execute arbitrary Ja...
The Lab · 2026-03-29 21:26:56 · GitHub Issues
A critical remote code execution (RCE) vulnerability has been patched in the popular Node.js library happy-dom, a key component for simulating a browser environment in testing frameworks. The flaw, tracked as CVE-2026-33943, resides in the library's `ECMAScriptModuleCompiler`. It allows an attacker to inject arbitrary ...
The Lab · 2026-03-31 01:27:07 · GitHub Issues
A critical security vulnerability in the popular JavaScript testing library happy-dom has been disclosed, exposing projects to potential remote code execution (RCE) attacks. The flaw, tracked as CVE-2026-33943, resides in the library's `ECMAScriptModuleCompiler`. It allows an attacker to inject arbitrary JavaScript exp...