A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.

Project Subscriptions

Vendors Products
Cleverbrush Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 25 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component.
Title cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution
First Time appeared Cleverbrush
Cleverbrush deep
Cleverbrush framework
Weaknesses CWE-1321
CWE-94
CPEs cpe:2.3:a:cleverbrush:deep:*:*:*:*:*:*:*:*
cpe:2.3:a:cleverbrush:framework:*:*:*:*:*:*:*:*
Vendors & Products Cleverbrush
Cleverbrush deep
Cleverbrush framework
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-25T06:00:13.406Z

Reserved: 2026-08-24T23:08:18.011Z

Link: CVE-2026-78654

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T06:19:01.940

Modified: 2026-08-25T06:19:01.940

Link: CVE-2026-78654

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:30:12Z

Weaknesses