CVE-2026-25047Disclosure(sharpred / deephas)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch sharpred deephas systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • deephas

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-01-29); latest day: 2
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
deephas

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-01-29: 2Mentions · 2026-01-30: 2PoC Mentioned / Linked · 2026-01-29: 1Patch / Workaround · 2026-01-30: 1Technical Details · 2026-01-29: 2Technical Details · 2026-01-30: 201-2901-30
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-01-292
Disclosure2
2026-01-302
Disclosure1Patch1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A Prototype Pollution vulnerability (CVE-2026-25047) affects deephas prior to version 1.0.8. Upgrade to mitigate the risk. #deephas #PrototypePollution #infosec https://www.pulsepatch.io/posts/cve-2026-25047-deephas-prototype-pollution

    Post summary

    The post warns of a Prototype Pollution flaw in deephas before 1.0.8 and advises upgrading to mitigate the risk.

    0000040
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25047 Prototype Pollution Vulnerability in deepHas npm Package Version ... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25047 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    A newly disclosed prototype pollution vulnerability in the deepHas npm package (CVE‑2026‑25047) is highlighted with a link for further details, but no exploits, patches, or PoC are provided.

    00000102
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25047 deepHas provides a test for the existence of a nested object key and optionally returns that key. A prototype pollution vulnerability exists in version 1.0.7 of the d… https://www.cve.org/CVERecord?id=CVE-2026-25047

    Post summary

    CVE-2026-25047 is disclosed as a prototype pollution flaw in deepHas v1.0.7, with basic technical details but no evidence of exploitation or patch availability.

    00000291
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-25047: deepHas vulnerable to Prototype ... Prototype pollution in deepHas v1.0.7 exploits object key testing to inject malicious properties via constructor.protot... https://zerodaysignal.com/vulnerability/CVE-2026-25047 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces a prototype pollution vulnerability in deepHas v1.0.7 (CVE-2026-25047) and provides a link likely containing further details, but does not mention an exploit, patch, or active exploitation.

    0000065
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsharpreddeephas1.0.7node.js-

Explore more