CVE-2026-78180
alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.
| CWE | CWE-1321 CWE-94 |
| Vendor | alibaba-fusion |
| Product | next |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for alibaba-fusion next
Be the first to know when new high vulnerabilities affecting alibaba-fusion next are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
alibaba-fusion / next
1.27.0 1.27.1 1.27.2 1.27.3 1.27.4 1.27.5 1.27.6 1.27.7 1.27.8 1.27.9 1.27.10 1.27.11 1.27.12 1.27.13 1.27.14 1.27.15 1.27.16 1.27.17 1.27.18 1.27.19 1.27.20 1.27.21 1.27.22 1.27.23 1.27.24 1.27.25 1.27.26 1.27.27 1.27.28 1.27.29 1.27.30 1.27.31 1.27.32 1.27.33 1.27.34
References
Credits
๐ wjm3 (VulDB User) VulDB CNA Team