PT-2026-5362 · Npm · Deephas

Kevgeoleo

+2

·

Published

2026-01-29

·

Updated

2026-01-30

·

CVE-2026-25047

CVSS v4.0

9.4

Critical

VectorAV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions deephas version 1.0.7 deephas versions prior to 1.0.8
Description A prototype pollution issue exists in the deephas npm package. This allows an attacker to modify global object behavior by injecting properties into Object.prototype. The issue resides in the add() function and indexer() function within deepHas.js. The vulnerability can be bypassed by manipulating Object.prototype.hasOwnProperty or String.prototype.indexOf. Exploitation can lead to authentication bypass, denial of service, and potentially remote code execution if polluted properties are passed to vulnerable sinks.
Recommendations deephas versions prior to 1.0.8 should be updated to version 1.0.8 or later.

Exploit

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-25047
GHSA-2733-6C58-PF27

Affected Products

Deephas