{"id":"CVE-2026-78180","summary":"alibaba-fusion next deepMerge index.tsx ConfigProvider.getContextProps prototype pollution","details":"A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.","modified":"2026-08-27T11:31:08.215460162Z","published":"2026-08-24T03:15:08.568Z","database_specific":{"cwe_ids":["CWE-1321","CWE-94"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78180.json","cna_assigner":"VulDB"},"references":[{"type":"WEB","url":"https://github.com/alibaba-fusion/next/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/78xxx/CVE-2026-78180.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-78180"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-78180"},{"type":"ADVISORY","url":"https://vuldb.com/submit/884184"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/394564"},{"type":"REPORT","url":"https://github.com/alibaba-fusion/next/issues/5101"},{"type":"REPORT","url":"https://vuldb.com/vuln/394564/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/alibaba-fusion/next","events":[{"introduced":"fffb897cd22b4ad38055dc1d84a7d9cc5074e280"},{"last_affected":"25f55e66daa996d61f4a1bbba6524352dc9f04fe"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"1.27.0"},{"last_affected":"1.27.0"},{"introduced":"1.27.1"},{"last_affected":"1.27.1"},{"introduced":"1.27.2"},{"last_affected":"1.27.2"},{"introduced":"1.27.3"},{"last_affected":"1.27.3"},{"introduced":"1.27.4"},{"last_affected":"1.27.4"},{"introduced":"1.27.5"},{"last_affected":"1.27.5"},{"introduced":"1.27.6"},{"last_affected":"1.27.6"},{"introduced":"1.27.7"},{"last_affected":"1.27.7"},{"introduced":"1.27.8"},{"last_affected":"1.27.8"},{"introduced":"1.27.9"},{"last_affected":"1.27.9"},{"introduced":"1.27.10"},{"last_affected":"1.27.10"},{"introduced":"1.27.11"},{"last_affected":"1.27.11"},{"introduced":"1.27.12"},{"last_affected":"1.27.12"},{"introduced":"1.27.13"},{"last_affected":"1.27.13"},{"introduced":"1.27.14"},{"last_affected":"1.27.14"},{"introduced":"1.27.15"},{"last_affected":"1.27.15"},{"introduced":"1.27.16"},{"last_affected":"1.27.16"},{"introduced":"1.27.17"},{"last_affected":"1.27.17"},{"introduced":"1.27.18"},{"last_affected":"1.27.18"},{"introduced":"1.27.19"},{"last_affected":"1.27.19"},{"introduced":"1.27.20"},{"last_affected":"1.27.20"},{"introduced":"1.27.21"},{"last_affected":"1.27.21"},{"introduced":"1.27.22"},{"last_affected":"1.27.22"},{"introduced":"1.27.23"},{"last_affected":"1.27.23"},{"introduced":"1.27.24"},{"last_affected":"1.27.24"},{"introduced":"1.27.25"},{"last_affected":"1.27.25"},{"introduced":"1.27.26"},{"last_affected":"1.27.26"},{"introduced":"1.27.27"},{"last_affected":"1.27.27"},{"introduced":"1.27.28"},{"last_affected":"1.27.28"},{"introduced":"1.27.29"},{"last_affected":"1.27.29"},{"introduced":"1.27.30"},{"last_affected":"1.27.30"},{"introduced":"1.27.31"},{"last_affected":"1.27.31"},{"introduced":"1.27.32"},{"last_affected":"1.27.32"},{"introduced":"1.27.33"},{"last_affected":"1.27.33"},{"introduced":"1.27.34"},{"last_affected":"1.27.34"}]}}],"versions":["1.27.0","1.27.1","1.27.10","1.27.11","1.27.12","1.27.13","1.27.14","1.27.15","1.27.16","1.27.17","1.27.18","1.27.19","1.27.2","1.27.20","1.27.21","1.27.22","1.27.23","1.27.24","1.27.25","1.27.26","1.27.27","1.27.28","1.27.29","1.27.3","1.27.30","1.27.31","1.27.32","1.27.33","1.27.34","1.27.4","1.27.5","1.27.6","1.27.7","1.27.8","1.27.9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-78180.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}