Back to search
CVE-2024-51757
Published: Nov 6, 2024
Modified: Nov 6, 2024
PUBLISHED
Description
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom. Users are advised to upgrade to version 15.10.2. There are no known workarounds for this vulnerability.
| Vendor | Product | Versions |
|---|---|---|
capricorn86 | happy-dom | affected < 15.10.2 |
References
https://github.com/capricorn86/happy-dom/issues/1585
x_refsource_MISC
https://github.com/capricorn86/happy-dom/pull/1586
x_refsource_MISC
https://github.com/capricorn86/happy-dom/releases/tag/v15.10.2
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now