← Back to overview

A prototype pollution vulnerability (CVE-2026-78654) has been discovered in the cleverbrush framework and deep library up to version 4.4.0. The vulnerability exists in the deepExtend function within libs/deep/src/deepExtend.ts, allowing improperly controlled modification of object prototype attributes. Remote exploitation is possible and a public exploit has been disclosed. The vulnerability has been patched in version 4.4.1 with commit 810398c1308c500c3b8b6af380b5a89371389327. Users are strongly advised to upgrade the affected component immediately to mitigate risk.

Affected products

  • cleverbrush deep up to 4.4.0
  • cleverbrush framework

Related CVE's

  • CVE-2026-78654

Categories

  • Supply Chain & Dependencies
  • Web Technologies