CVE-2026-78654 | cleverbrush framework/deep up to 4.4.0 deepExtend.ts deepExtend prototype pollution (Issue 213)
A vulnerability identified as critical has been detected in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes.
This vulnerability is referenced as CVE-2026-78654. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
You should upgrade the affected component.VulDB Recent EntriesRead More