deepHas vulnerable to Prototype Pollution via constructor.prototype
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.4epss 0.7%
from disclosure to weapon2 days
Published on NVDJan 29
1st PoC+2d
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Affected products
sharpred · deepHaspublic PoCs found — 2
exploitdbwww.exploit-db.com/exploits/52528unverifiedgithubgithub.com/mbanyamer/deephas-1.0.7-Prototype-Pollution-PoC-CVE-2026-25047-★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.