Junglewise Threat Intelligence

CVE-2026-78654: Cleverbrush deep prototype pollution in deepExtend

CVE-2026-78654 · Severity: high · CVSS 7.3 · Published 2026-08-25

Executive brief

Cleverbrush deep is a library used to recursively merge JavaScript objects in full-stack TypeScript applications. A prototype pollution vulnerability in the deepExtend() function allows remote attackers to inject malicious properties into object prototypes, potentially corrupting application data or enabling remote code execution. The vulnerability affects versions up to 4.4.0 and has been patched in version 4.4.1.

Technical details

The vulnerability is a prototype pollution flaw in the deepExtend() function located in libs/deep/src/deepExtend.ts. The function recursively merges objects without properly sanitizing keys, allowing an attacker to inject properties like "__proto__", "constructor", or "prototype" that pollute the base Object prototype. Remote exploitation is possible if the application passes untrusted user input to deepExtend(). An attacker can modify or add properties to the Object prototype, affecting all objects in the application and potentially leading to data corruption, authentication bypass, or code execution. The fix is available in version 4.4.1 (patch commit 810398c1308c500c3b8b6af380b5a89371389327) which prevents merging prototype-polluting keys.

Affected products

  • Cleverbrush deep up to 4.4.0

Timeline

  • 2026-08-25: disclosed
  • 2026-07-13: patched: Fix available in version 4.4.1

References