PT-2026-79815 · Unknown · Alibaba-Fusion Next
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
alibaba-fusion next versions prior to 1.27.35
Description
A prototype pollution flaw exists in the
deepMerge component within the components/dialog/index.tsx file. This occurs when the ConfigProvider.getContextProps() function improperly handles the locale argument, allowing a remote attacker to modify object prototype attributes.Recommendations
Update alibaba-fusion next to version 1.27.35 or later.
As a temporary mitigation, restrict or validate the input passed to the
locale argument in the ConfigProvider.getContextProps() function.Exploit
Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alibaba-Fusion Next