PatchSiren

cleverbrush CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM cleverbrush CVE published 2026-08-25

CVE-2026-78654

A vulnerability was found in the cleverbrush framework and deep up to version 4.4.0, affecting the deepExtend function in libs/deep/src/deepExtend.ts. This issue allows for improperly controlled modification of object prototype attributes, and remote exploitation is possible. The vulnerability is fixed in version 4.4.1 with patch 810398c1308c500c3b8b6af380b5a89371389327.