CVE-2026-78654 | cleverbrush framework/deep up to 4.4.0 deepExtend.ts deepExtend prototype pollution (Issue 213)

SecurityVulns

A vulnerability identified as critical has been detected in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes.

This vulnerability is referenced as CVE-2026-78654. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

You should upgrade the affected component.VulDB Recent EntriesRead More