PT-2026-81180 · Unknown+1 · Cleverbrush Framework+1

·

CVE-2026-78654

·

Published

2026-08-25

·

Updated

2026-08-25

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions cleverbrush framework and deep versions prior to 4.4.1
Description Prototype Pollution occurs in the deepExtend() function within the libs/deep/src/deepExtend.ts file. This issue allows for the improperly controlled modification of object prototype attributes, which can be exploited remotely.
Recommendations Upgrade to version 4.4.1.

Exploit

Fix

Code Injection

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78654

Affected Products

Cleverbrush Framework
Deep