
A code injection vulnerability (CVE-2026-33943) in `Happy DOM ECMAScriptModuleCompiler` can lead to arbitrary code execution via unsanitized export names. #CodeInjection #JavaScript #Security https://www.pulsepatch.io/posts/cve-2026-33943-happy-dom-ecmascriptmodulecompiler-code-execution
Post summary
The post announces a new code injection vulnerability in Happy DOM’s ECMAScriptModuleCompiler that can lead to arbitrary code execution via unsanitized export names, but it does not provide a PoC, exploit tool, active exploitation evidence, or patch details.



