A major vulnerability has been discovered in Happy DOM, a popular JavaScript DOM implementation. The vulnerability affects versions up to v19.

This vulnerability could allow attackers to perform Remote Code Execution (RCE) attacks, potentially affecting the package's 2.7 million weekly users. The issue arises because the Node.js VM Context used by Happy DOM is not a fully isolated environment. As a result, it could allow untrusted code to escape and gain access to underlying system functions.
See also: Oracle E-Business Suite: New RCE vulnerability exposes data
The main issue is that Happy DOM has JavaScript evaluation enabled by default, a detail that may not be apparent to all developers using the library. This default configuration becomes a security risk when the environment executes untrusted code. An attacker can create malicious JavaScript that traverses the constructor chain to gain access to the process-level Function constructor. This allows them to execute code outside of the intended sandbox environment, leading to a full VM escape.
The type of module system used, whether CommonJS or ESM, determines the extent of the attacker's control. In a CommonJS environment, an attacker can gain access to the require() function, which allows them to load Node.js modules and perform unauthorized actions.

The implications of this vulnerability are far-reaching, especially for applications that use Server-Side Rendering (SSR) or testing frameworks that process external content. An attacker could inject a malicious script into user-controlled HTML, which would then be executed on the server. Successful exploitation could lead to several devastating results:
– Data Extraction: Gaining access to sensitive information such as environment variables, configuration files, and other secrets.
– Lateral Movement: Using network access to connect to other internal systems. Although Happy DOM has some network protections, a compromised process could bypass them.
– Code Execution: Gaining access to subprocesses to execute arbitrary commands on the server.
– Persistence: Modifying the file system to maintain a long-term presence on the compromised system.
See also: Vulnerabilities in Microsoft Defender allow authentication bypass
Happy DOM Vulnerability: Protection
The developers of Happy DOM have released an update to address this vulnerability. Users are advised to take immediate action to protect their systems. The recommended action is to upgrade to Happy DOM v20 or later. This update disables JavaScript evaluation by default and includes a warning if it is enabled in an environment that is considered insecure.
See also: GitHub Copilot: Vulnerability allows code extraction from private repositories

For users who require JavaScript evaluation, it is critical to run Node.js with the --disallow-code-generation-from-strings flag. This setting prevents the use of eval() and Function() at the process level, closing the loophole that allows VM escape. If an immediate update is not possible, developers should disable JavaScript evaluation manuallyunless the content being processed is from a fully trusted source.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
