No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 25 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 25 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been found in cleverbrush framework and deep up to 4.4.0. This impacts the function deepExtend of the file libs/deep/src/deepExtend.ts. The manipulation leads to improperly controlled modification of object prototype attributes. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Upgrading to version 4.4.1 will fix this issue. The identifier of the patch is 810398c1308c500c3b8b6af380b5a89371389327. You should upgrade the affected component. | |
| Title | cleverbrush framework/deep deepExtend.ts deepExtend prototype pollution | |
| First Time appeared |
Cleverbrush
Cleverbrush deep Cleverbrush framework |
|
| Weaknesses | CWE-1321 CWE-94 |
|
| CPEs | cpe:2.3:a:cleverbrush:deep:*:*:*:*:*:*:*:* cpe:2.3:a:cleverbrush:framework:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cleverbrush
Cleverbrush deep Cleverbrush framework |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-25T13:17:33.100Z
Reserved: 2026-08-24T23:08:18.011Z
Link: CVE-2026-78654
Updated: 2026-08-25T13:17:09.195Z
Status : Received
Published: 2026-08-25T06:19:01.940
Modified: 2026-08-25T14:16:57.247
Link: CVE-2026-78654
No data.
OpenCVE Enrichment
Updated: 2026-08-25T07:30:12Z