An open index of dependabot pull requests across open source projects.

happy-dom

Ecosystem:
npm
Package URL:
pkg:npm/happy-dom
Total PRs:
6,558 Dependabot PRs
Latest PR:
about 6 hours ago
Unique Repositories:
2,501 repositories
Unique Repos (30 days):
445 repositories
Security Advisories
Happy DOM's fetch credentials include uses page-origin cookies instead of target-origin cookies
GHSA-w4gp-fjgq-3q4g CVE-2026-34226 HIGH published 6 months ago • updated 5 days ago
### Summary `happy-dom` may attach cookies from the current page origin (`window.location`) instead of the request target URL when `fetch(..., { cr...
Happy DOM: VM Context Escape can lead to Remote Code Execution
GHSA-37j7-fg3j-429f CVE-2025-61927 CRITICAL published 11 months ago • updated 7 days ago
# Escape of VM Context gives access to process level functionality ## Summary Happy DOM v19 and lower contains a security vulnerability that puts ...
happy-dom allows for server side code to be executed by a <script> tag
GHSA-96g7-g7g9-jxw8 CVE-2024-51757 CRITICAL published almost 2 years ago • updated 8 days ago
### Impact Consumers of the NPM package `happy-dom` ### Patches The security vulnerability has been patched in v15.10.2 ### Workarounds No easy w...
Happy DOM ECMAScriptModuleCompiler: unsanitized export names are interpolated as executable code
GHSA-6q6h-j7hj-3r64 CVE-2026-33943 HIGH published 6 months ago • updated 11 days ago
### Summary A code injection vulnerability in `ECMAScriptModuleCompiler` allows an attacker to achieve Remote Code Execution (RCE) by injecting ar...
happy-dom's `--disallow-code-generation-from-strings` is not sufficient for isolating untrusted JavaScript
GHSA-qpm2-6cq5-7pq5 CVE-2025-62410 CRITICAL published 11 months ago • updated 2 days ago
### Summary The mitigation proposed in GHSA-37j7-fg3j-429f for disabling eval/Function when executing untrusted code in happy-dom does not suffice,...
Recent PRs
Package Details
Name: happy-dom
Ecosystem: npm
PURL Type: npm
Package URL: pkg:npm/happy-dom
JSON API: View JSON
Security Advisories

5

Active advisories
CRITICAL 3
HIGH 2
View All npm Advisories
Package Information
Description:

Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. It includes many web standards from WHATWG DOM and HTML.

Repository: https://github.com/capricorn86/happy-dom
Homepage: https://github.com/capricorn86/happy-dom
Latest Release: 15.11.7
almost 2 years ago
Dependent Repos: 3,800
Dependent Packages: 1,713
Downloads: 4,725,430
Ranking: Top 0.3846% by dependent repos Top 0.2292% by downloads Top 0.0622% by dependent pkgs
PR Status
Open 3,007 (45.9%)
Merged 434 (6.6%)
Closed 2,660 (40.6%)
PR Types
Major 2,243 (34.2%)
Minor 2,359 (36.0%)
Patch 1,498 (22.8%)