CVE-2026-25047 PUBLISHED

deepHas vulnerable to Prototype Pollution via constructor.prototype

Assigner: GitHub_M
Reserved: 28.01.2026 Published: 29.01.2026 Updated: 02.02.2026

deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSS Score: 9.4

Product Status

Vendor sharpred
Product deepHas
Versions
  • Version < 1.0.7 is affected

References

Problem Types

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CWE