deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2733-6c58-pf27 | deepHas vulnerable to Prototype Pollution via constructor.prototype |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 30 Jan 2026 07:00:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8. | |
| Title | deepHas vulnerable to Prototype Pollution via constructor.prototype | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-29T21:39:48.498Z
Reserved: 2026-01-28T14:50:47.886Z
Link: CVE-2026-25047
No data.
Status : Received
Published: 2026-01-29T22:15:55.647
Modified: 2026-01-29T22:15:55.647
Link: CVE-2026-25047
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA