A prototype pollution vulnerability (CVE-2026-78654) has been discovered in the cleverbrush framework and deep library up to version 4.4.0. The vulnerability exists in the deepExtend function within libs/deep/src/deepExtend.ts, allowing improperly controlled modification of object prototype attributes. Remote exploitation is possible and a public exploit has been disclosed. The vulnerability has been patched in version 4.4.1 with commit 810398c1308c500c3b8b6af380b5a89371389327. Users are strongly advised to upgrade the affected component immediately to mitigate risk.