A vulnerability was found in happy-dom 15.10.2/20.0.0/20.0.2. It has been declared as critical. This affects an unknown part of the component ECMAScriptModuleCompiler. Such manipulation leads to code injection.
This vulnerability is listed as CVE-2026-33943. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.