CVE-2026-78180

Source
https://cve.org/CVERecord?id=CVE-2026-78180
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78180.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-78180
Published
2026-08-24T03:15:08.568Z
Modified
2026-08-27T11:31:08.215460162Z
Severity
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution
Details

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78180.json",
    "cwe_ids": [
        "CWE-1321",
        "CWE-94"
    ],
    "cna_assigner": "VulDB"
}
References

Affected packages

Git / github.com/alibaba-fusion/next

Affected ranges

Type
GIT
Repo
https://github.com/alibaba-fusion/next
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "1.27.0"
        },
        {
            "last_affected": "1.27.0"
        },
        {
            "introduced": "1.27.1"
        },
        {
            "last_affected": "1.27.1"
        },
        {
            "introduced": "1.27.2"
        },
        {
            "last_affected": "1.27.2"
        },
        {
            "introduced": "1.27.3"
        },
        {
            "last_affected": "1.27.3"
        },
        {
            "introduced": "1.27.4"
        },
        {
            "last_affected": "1.27.4"
        },
        {
            "introduced": "1.27.5"
        },
        {
            "last_affected": "1.27.5"
        },
        {
            "introduced": "1.27.6"
        },
        {
            "last_affected": "1.27.6"
        },
        {
            "introduced": "1.27.7"
        },
        {
            "last_affected": "1.27.7"
        },
        {
            "introduced": "1.27.8"
        },
        {
            "last_affected": "1.27.8"
        },
        {
            "introduced": "1.27.9"
        },
        {
            "last_affected": "1.27.9"
        },
        {
            "introduced": "1.27.10"
        },
        {
            "last_affected": "1.27.10"
        },
        {
            "introduced": "1.27.11"
        },
        {
            "last_affected": "1.27.11"
        },
        {
            "introduced": "1.27.12"
        },
        {
            "last_affected": "1.27.12"
        },
        {
            "introduced": "1.27.13"
        },
        {
            "last_affected": "1.27.13"
        },
        {
            "introduced": "1.27.14"
        },
        {
            "last_affected": "1.27.14"
        },
        {
            "introduced": "1.27.15"
        },
        {
            "last_affected": "1.27.15"
        },
        {
            "introduced": "1.27.16"
        },
        {
            "last_affected": "1.27.16"
        },
        {
            "introduced": "1.27.17"
        },
        {
            "last_affected": "1.27.17"
        },
        {
            "introduced": "1.27.18"
        },
        {
            "last_affected": "1.27.18"
        },
        {
            "introduced": "1.27.19"
        },
        {
            "last_affected": "1.27.19"
        },
        {
            "introduced": "1.27.20"
        },
        {
            "last_affected": "1.27.20"
        },
        {
            "introduced": "1.27.21"
        },
        {
            "last_affected": "1.27.21"
        },
        {
            "introduced": "1.27.22"
        },
        {
            "last_affected": "1.27.22"
        },
        {
            "introduced": "1.27.23"
        },
        {
            "last_affected": "1.27.23"
        },
        {
            "introduced": "1.27.24"
        },
        {
            "last_affected": "1.27.24"
        },
        {
            "introduced": "1.27.25"
        },
        {
            "last_affected": "1.27.25"
        },
        {
            "introduced": "1.27.26"
        },
        {
            "last_affected": "1.27.26"
        },
        {
            "introduced": "1.27.27"
        },
        {
            "last_affected": "1.27.27"
        },
        {
            "introduced": "1.27.28"
        },
        {
            "last_affected": "1.27.28"
        },
        {
            "introduced": "1.27.29"
        },
        {
            "last_affected": "1.27.29"
        },
        {
            "introduced": "1.27.30"
        },
        {
            "last_affected": "1.27.30"
        },
        {
            "introduced": "1.27.31"
        },
        {
            "last_affected": "1.27.31"
        },
        {
            "introduced": "1.27.32"
        },
        {
            "last_affected": "1.27.32"
        },
        {
            "introduced": "1.27.33"
        },
        {
            "last_affected": "1.27.33"
        },
        {
            "introduced": "1.27.34"
        },
        {
            "last_affected": "1.27.34"
        }
    ]
}

Affected versions

1.*
1.27.0
1.27.1
1.27.10
1.27.11
1.27.12
1.27.13
1.27.14
1.27.15
1.27.16
1.27.17
1.27.18
1.27.19
1.27.2
1.27.20
1.27.21
1.27.22
1.27.23
1.27.24
1.27.25
1.27.26
1.27.27
1.27.28
1.27.29
1.27.3
1.27.30
1.27.31
1.27.32
1.27.33
1.27.34
1.27.4
1.27.5
1.27.6
1.27.7
1.27.8
1.27.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78180.json"