Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 24 Aug 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity. | |
| Title | alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution | |
| First Time appeared |
Next
Next next |
|
| Weaknesses | CWE-1321 CWE-94 |
|
| CPEs | cpe:2.3:a:next:next:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Next
Next next |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-08-24T03:15:08.568Z
Reserved: 2026-08-23T16:03:29.986Z
Link: CVE-2026-78180
No data.
Status : Received
Published: 2026-08-24T04:16:58.647
Modified: 2026-08-24T04:16:58.647
Link: CVE-2026-78180
No data.
OpenCVE Enrichment
Updated: 2026-08-24T05:00:04Z