FixVibe

// код / прожектор

deephas Prototype-Pollution Advisory

A vulnerable deephas dependency can put deep-path object handling on a prototype-pollution path.

What it is

Prototype pollution lets an attacker-controlled key change the behavior of every object in a Node.js process. CVE-2020-28271 puts that bug in deephas versions 1.0.0 through 1.0.5, so any code path that passes user input to its deep-path helpers is exposed.

How it happens

deephas reads and writes nested object properties by path. In affected versions, a path that walks through `__proto__` writes onto the shared object prototype instead of the target object, so the change shows up on every object in the process.

What an attacker gets

If your app passes attacker-controlled keys or object paths to an affected deephas release, prototype pollution can change inherited object behavior across the process, from crashing it to bypassing checks that read default properties.

// what fixvibe reports

What FixVibe reports

Runs when you connect a GitHub repository, on Pro and above. Each finding shows the file and line, its severity and fix steps you can paste into your AI coding tool.

How to fix it

Upgrade deephas to 1.0.8 or replace it with a maintained deep-path utility, regenerate the active lockfile, rebuild and redeploy the artifact, and review call sites that pass user-controlled keys such as object paths. Keep input schemas stripping prototype keys before they reach object merge or path helpers.

// запусти на своём приложении

Продолжай выпускать продукт, пока FixVibe следит за рисками.

Connect a GitHub repo to check its code, dependencies and workflows.

Исходный код
198
тестов в этой категории
модулей
155
проверок исходный код
GitHub repos
190+
checks on each connected repo
Connect GitHub →

// актуальные проверки · практичные фиксы · выпускай увереннее

deephas Prototype-Pollution Advisory: what it is and how to fix it · FixVibe