PT-2026-81180 · Unknown+1 · Cleverbrush Framework+1
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
cleverbrush framework and deep versions prior to 4.4.1
Description
Prototype Pollution occurs in the
deepExtend() function within the libs/deep/src/deepExtend.ts file. This issue allows for the improperly controlled modification of object prototype attributes, which can be exploited remotely.Recommendations
Upgrade to version 4.4.1.
Exploit
Fix
Code Injection
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cleverbrush Framework
Deep