CVE-2026-25047: Sharpred Deephas
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
Affected products
- Sharpred Deephas: version 1.0.7 only
Published 2026-01-29. Last modified 2026-06-17.