A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.
Metrics
Affected Vendors & Products
References
History
Mon, 24 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity. | |
| Title | alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution | |
| First Time appeared |
Next
Next next |
|
| Weaknesses | CWE-1321 CWE-94 |
|
| CPEs | cpe:2.3:a:next:next:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Next
Next next |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-24T03:15:08.568Z
Reserved: 2026-08-23T16:03:29.986Z
Link: CVE-2026-78180
No data.
Status : Received
Published: 2026-08-24T04:16:58.647
Modified: 2026-08-24T04:16:58.647
Link: CVE-2026-78180
No data.
OpenCVE Enrichment
Updated: 2026-08-24T05:00:04Z