Description
A prototype pollution vulnerability exists in version 1.0.7 of the deephas npm package that allows an attacker to modify global object behavior. This issue was fixed in version 1.0.8.
Recommendation
Update the deephas package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.0.8
- Patched version(s): 1.0.8
References
Related Issues
- scimPatch vulnerable to prototype pollution via unfiltered keys in patch - CVE-2026-48170
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash.unset - CVE-2026-2950
- dottie is vulnerable to Prototype Pollution bypass via non-first path segments in set() and transform() - CVE-2026-27837
- lodash vulnerable to Prototype Pollution via array path bypass in `_.unset` and `_.omit` - lodash-es - CVE-2026-2950
You might also like:
- Tags:
- npm
- deephas
Anything's wrong? Let us know Last updated on February 27, 2026


