What it is
Prototype pollution lets an attacker-controlled key change the behavior of every object in a Node.js process. CVE-2020-28271 puts that bug in deephas versions 1.0.0 through 1.0.5, so any code path that passes user input to its deep-path helpers is exposed.
How it happens
deephas reads and writes nested object properties by path. In affected versions, a path that walks through `__proto__` writes onto the shared object prototype instead of the target object, so the change shows up on every object in the process.
What an attacker gets
If your app passes attacker-controlled keys or object paths to an affected deephas release, prototype pollution can change inherited object behavior across the process, from crashing it to bypassing checks that read default properties.
// what fixvibe reports
What FixVibe reports
Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.
How to fix it
Upgrade deephas to 1.0.8 or replace it with a maintained deep-path utility, regenerate the active lockfile, rebuild and redeploy the artifact, and review call sites that pass user-controlled keys such as object paths. Keep input schemas stripping prototype keys before they reach object merge or path helpers.
