Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2733-6c58-pf27 | deepHas vulnerable to Prototype Pollution via constructor.prototype |
Wed, 25 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:sharpred:deephas:1.0.7:*:*:*:*:node.js:*:* | |
| Metrics |
cvssV3_1
|
Mon, 02 Feb 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Jan 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sharpred
Sharpred deephas |
|
| Vendors & Products |
Sharpred
Sharpred deephas |
Thu, 29 Jan 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8. | |
| Title | deepHas vulnerable to Prototype Pollution via constructor.prototype | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-02T16:35:22.701Z
Reserved: 2026-01-28T14:50:47.886Z
Link: CVE-2026-25047
Updated: 2026-01-30T14:48:56.330Z
Status : Analyzed
Published: 2026-01-29T22:15:55.647
Modified: 2026-02-25T15:13:28.610
Link: CVE-2026-25047
No data.
OpenCVE Enrichment
Updated: 2026-04-18T18:45:05Z
Github GHSA