deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
History

Fri, 30 Jan 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Sharpred
Sharpred deephas
Vendors & Products Sharpred
Sharpred deephas

Thu, 29 Jan 2026 22:00:00 +0000

Type Values Removed Values Added
Description deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
Title deepHas vulnerable to Prototype Pollution via constructor.prototype
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-01-29T21:39:48.498Z

Reserved: 2026-01-28T14:50:47.886Z

Link: CVE-2026-25047

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-01-29T22:15:55.647

Modified: 2026-01-29T22:15:55.647

Link: CVE-2026-25047

cve-icon Redhat

No data.