FixVibe

// code / spotlight

deephas Prototype-Pollution Advisory

A vulnerable deephas dependency can put deep-path object handling on a prototype-pollution path.

What it is

Prototype pollution lets an attacker-controlled key change the behavior of every object in a Node.js process. CVE-2020-28271 puts that bug in deephas versions 1.0.0 through 1.0.5, so any code path that passes user input to its deep-path helpers is exposed.

How it happens

deephas reads and writes nested object properties by path. In affected versions, a path that walks through `__proto__` writes onto the shared object prototype instead of the target object, so the change shows up on every object in the process.

What an attacker gets

If your app passes attacker-controlled keys or object paths to an affected deephas release, prototype pollution can change inherited object behavior across the process, from crashing it to bypassing checks that read default properties.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade deephas to 1.0.8 or replace it with a maintained deep-path utility, regenerate the active lockfile, rebuild and redeploy the artifact, and review call sites that pass user-controlled keys such as object paths. Keep input schemas stripping prototype keys before they reach object merge or path helpers.

// run it on your own app

Terus rilis sementara FixVibe yang berjaga.

Connect a GitHub repo to check its code, dependencies and workflows.

Kode sumber
198
tes yang dijalankan di kategori ini
modules
155
check kode sumber khusus
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// latest checks · practical fixes · ship with confidence

deephas Prototype-Pollution Advisory: what it is and how to fix it · FixVibe