---
id: CVE-2025-62410
title: >-
  In versions before 20.0.2, it was found that
  --disallow-code-generation-from-strings is not sufficient for isolating
  untrusted JavaScript in happy-dom
summary: >-
  In versions before 20.0.2, it was found that
  --disallow-code-generation-from-strings is not sufficient for isolating
  untrusted JavaScript in happy-dom. The untrusted script and the rest of the
  application still run in the same Isolate/pr…
severity: none
cwe:
  - CWE-1321
published: '2025-10-15'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-62410'
references:
  - url: >-
      https://github.com/capricorn86/happy-dom/commit/f4bd4ebe3fe5abd2be2bcea1c07043c8b0b70eea
    label: security-advisories@github.com
  - url: >-
      https://github.com/capricorn86/happy-dom/security/advisories/GHSA-qpm2-6cq5-7pq5
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00352
epssPercentile: 0.26755
ingestedAt: '2026-10-08T11:31:27.443Z'
---

## Overview

In versions before 20.0.2, it was found that --disallow-code-generation-from-strings is not sufficient for isolating untrusted JavaScript in happy-dom. The untrusted script and the rest of the application still run in the same Isolate/process, so attackers can deploy prototype pollution payloads to hijack important references like "process" in the example below, or to hijack control flow via flipping checks of undefined property. This vulnerability is due to an incomplete fix for CVE-2025-61927. The vulnerability is fixed in 20.0.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
