deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sharpred:deephas:1.0.7:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Mon, 02 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sharpred
Sharpred deephas |
|
| Vendors & Products |
Sharpred
Sharpred deephas |
Thu, 29 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8. | |
| Title | deepHas vulnerable to Prototype Pollution via constructor.prototype | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-01-29T21:39:48.498Z
Updated: 2026-02-02T16:35:22.701Z
Reserved: 2026-01-28T14:50:47.886Z
Link: CVE-2026-25047
Updated: 2026-01-30T14:48:56.330Z
Status : Analyzed
Published: 2026-01-29T22:15:55.647
Modified: 2026-02-25T15:13:28.610
Link: CVE-2026-25047
No data.