PT-2026-79815 · Unknown · Alibaba-Fusion Next

·

CVE-2026-78180

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions alibaba-fusion next versions prior to 1.27.35
Description A prototype pollution flaw exists in the deepMerge component within the components/dialog/index.tsx file. This occurs when the ConfigProvider.getContextProps() function improperly handles the locale argument, allowing a remote attacker to modify object prototype attributes.
Recommendations Update alibaba-fusion next to version 1.27.35 or later. As a temporary mitigation, restrict or validate the input passed to the locale argument in the ConfigProvider.getContextProps() function.

Exploit

Fix

Prototype Pollution

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78180

Affected Products

Alibaba-Fusion Next