Get real-time updates on Telegram
P5Verified
CVE-2025-62410: happy-dom < 20.0.2
CVE-2025-62410. EPSS 0.00352 (percentile 0.26673), scored 2026-10-06.
Affected technology
happy-dom · < 20.0.2
capricorn86
Description’s affected range: versions before 20.0.2
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · Passive user interaction
What an attacker can do
So attackers can deploy prototype pollution payloads to hijack important references like "process" in the example below, or to hijack control flow via flipping checks of undefined property. Vendor/CNA’s CVSS 4.0 assessment (base score 9.4/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-1321
- CCR priority
- 0.1 /100 (P5)
- EPSS
- 0.00352 · percentile 0.26778 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-62410.html