Product
CVE-2026-78654 is a prototype pollution vulnerability in the deepExtend function of the cleverbrush deep library (versions <= 4.4.0) that permits arbitrary modification of object prototype attributes.