Prototype Pollution Vulnerability in Alibaba-Fusion Next by Alibaba
CVE-2026-78180
6.9MEDIUM
What is CVE-2026-78180?
A security flaw has been identified in Alibaba-Fusion Next affecting the deepMerge component. The issue lies within the ConfigProvider.getContextProps function in components/dialog/index.tsx, where a manipulated argument locale can lead to unauthorized modifications of object prototype attributes. This vulnerability can be exploited remotely, posing a significant risk to systems utilizing certain versions of the product.
Affected Version(s)
next 1.27.0
next 1.27.1
next 1.27.2
