CYBER CODE RED

Get real-time updates on Telegram

P5Verified

CVE-2025-62410: happy-dom < 20.0.2

CVE-2025-62410. EPSS 0.00352 (percentile 0.26673), scored 2026-10-06.

Affected technology

happy-dom · < 20.0.2
capricorn86

Description’s affected range: versions before 20.0.2

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · Passive user interaction

What an attacker can do

So attackers can deploy prototype pollution payloads to hijack important references like "process" in the example below, or to hijack control flow via flipping checks of undefined property. Vendor/CNA’s CVSS 4.0 assessment (base score 9.4/10) rates confidentiality, integrity and availability impact as high.

Published

CWE
CWE-1321
CCR priority
0.1 /100 (P5)
EPSS
0.00352 · percentile 0.26778 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-62410.html