PT-2026-5362 · Npm · Deephas
Kevgeoleo
+2
·
Published
2026-01-29
·
Updated
2026-01-30
·
CVE-2026-25047
CVSS v4.0
9.4
Critical
| Vector | AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
deephas version 1.0.7
deephas versions prior to 1.0.8
Description
A prototype pollution issue exists in the deephas npm package. This allows an attacker to modify global object behavior by injecting properties into Object.prototype. The issue resides in the
add() function and indexer() function within deepHas.js. The vulnerability can be bypassed by manipulating Object.prototype.hasOwnProperty or String.prototype.indexOf. Exploitation can lead to authentication bypass, denial of service, and potentially remote code execution if polluted properties are passed to vulnerable sinks.Recommendations
deephas versions prior to 1.0.8 should be updated to version 1.0.8 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Deephas