Junglewise Threat Intelligence

CVE-2025-61927: Happy DOM VM Context Escape leading to Remote Code Execution

CVE-2025-61927 · Severity: medium · CVSS 4 · Published 2025-10-10

Technologies: Capricorn86 Happy-Dom. Vendors: npm.

Executive brief

Happy DOM is a JavaScript library that simulates a DOM environment for server-side rendering and testing. Versions 19 and below allow attackers to escape the VM sandbox by exploiting how JavaScript functions inherit from a global Function constructor, potentially gaining access to process-level functionality like file system and module loading. An attacker who can execute untrusted JavaScript code within Happy DOM can read environment variables, access configuration files, execute arbitrary commands, and modify the host system.

Technical details

The vulnerability is a code injection issue (CWE-94) caused by improper VM isolation in Node.js. Happy DOM wraps JavaScript execution in a VM Context; however, the JavaScript standard's prototype chain allows objects to reference the global Function constructor via constructor.constructor. An attacker can invoke this Function constructor with arbitrary code strings to execute code at the process level (outside the VM). JavaScript evaluation is enabled by default in versions 19 and below. With CommonJS, this grants access to the require() function to load arbitrary modules; with ESM, attackers gain direct process object access. The attack requires only the ability to inject or control HTML/JavaScript content passed to Happy DOM. Patched in version 20.0.0, which disables JavaScript evaluation by default and warns if it is enabled without the Node.js flag --disallow-code-generation-from-strings.

Affected products

  • Capricorn86 Happy DOM 0 to 19

Timeline

  • 2025-10-10: disclosed: Advisory published
  • 2025-10-10: patched: Happy DOM v20.0.0 released with JavaScript evaluation disabled by default

References

Related threats