CVE-2026-78180 | alibaba-fusion next up to 1.27.34 deepMerge index.tsx ConfigProvider.getContextProps locale prototype pollution (Issue 5101)

SecurityVulns

A vulnerability, which was classified as critical, has been found in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes.

This vulnerability was named CVE-2026-78180. The attack may be initiated remotely. There is no available exploit.

The reported GitHub issue was closed automatically due to inactivity.VulDB Recent EntriesRead More