A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.
History

Tue, 25 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.
Title cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution
First Time appeared Cleverbrush
Cleverbrush deep
Cleverbrush framework
Weaknesses CWE-1321
CWE-94
CPEs cpe:2.3:a:cleverbrush:deep:*:*:*:*:*:*:*:*
cpe:2.3:a:cleverbrush:framework:*:*:*:*:*:*:*:*
Vendors & Products Cleverbrush
Cleverbrush deep
Cleverbrush framework
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-25T06:00:13.406Z

Reserved: 2026-08-24T23:08:18.011Z

Link: CVE-2026-78654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T06:19:01.940

Modified: 2026-08-25T06:19:01.940

Link: CVE-2026-78654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:30:12Z