CVE-2026-33943Disclosure(capricorn86 / happy_dom)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch capricorn86 happy_dom systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to achieve Remote Code Execution (RCE) by injecting arbitrary JavaScript expressions inside `export { }` declarations in ES module scripts processed by happy-dom. The compiler directly interpolates unsanitized content into generated code as an executable expression, and the quote filter does not strip backticks, allowing template literal-based payloads to bypass sanitization. Version 20.8.8 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-917

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • happy_dom

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 2 mentions (2026-03-27); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Products
happy_dom

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Mentions · 2026-03-31: 1Patch / Workaround · 2026-03-27: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 1Technical Details · 2026-03-31: 103-2703-2803-31
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure1Patch1
2026-03-281
Disclosure1
2026-03-311
Disclosure1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Disclosure

    A code injection vulnerability (CVE-2026-33943) in `Happy DOM ECMAScriptModuleCompiler` can lead to arbitrary code execution via unsanitized export names. #CodeInjection #JavaScript #Security https://www.pulsepatch.io/posts/cve-2026-33943-happy-dom-ecmascriptmodulecompiler-code-execution

    Post summary

    The post announces a new code injection vulnerability in Happy DOM’s ECMAScriptModuleCompiler that can lead to arbitrary code execution via unsanitized export names, but it does not provide a PoC, exploit tool, active exploitation evidence, or patch details.

    0000020
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33943 Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in … https://www.cve.org/CVERecord?id=CVE-2026-33943

    Post summary

    CVE-2026-33943 is a code injection flaw impacting HappyDOM browsers v15.10.0–20.8.7; the brief entry supplies only basic disclosure info without evidence of exploitation or fixes.

    0000094
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33943 - High Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. In versions 15.10.0 through 20.8.7, a code injection vulnerability in `ECMAScriptModuleCompiler... https://www.thehackerwire.com/vulnerability/CVE-2026-33943/ https://t.co/DEnIQHRKcB

    Post summary

    CVE-2026-33943 is a high‑severity code injection flaw affecting Happy DOM versions 15.10.0 to 20.8.7, with details posted through an external link.

    0000038
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33943: HIGH] Security alert: Happy DOM versions 15.10.0-20.8.7 vulnerable to code injection via `ECMAScriptModuleCompiler`, enabling RCE. Update to version 20.8.8 to fix the issue. #CyberSecurity#cve,CVE-2026-33943,#cybersecurity https://cvefind.com/CVE-2026-33943

    Post summary

    The alert details that Happy DOM versions 15.10.0-20.8.7 are vulnerable to code injection (RCE) via ECMAScriptModuleCompiler and recommends updating to 20.8.8.

    0000034
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appcapricorn86happy_dom-node.js-

Explore more