CVE-2026-33943
Happy DOM Code Injection Vulnerability Enables Remote Code Execution.
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
A code injection vulnerability in the Happy DOM JavaScript library allows for remote code execution by injecting arbitrary JavaScript expressions into module scripts. This occurs because the `ECMAScriptModuleCompiler` directly interpolates unsanitized content into generated code. Systems processing specially crafted mo