GHSA-8mfc-fm4w-pgffMediumCVSS 7.3

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the...

Published
August 24, 2026
Last Modified
August 24, 2026

🔗 CVE IDs covered (1)

📋 Description

A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file components/dialog/index.tsx of the component deepMerge. Performing a manipulation of the argument locale results in improperly controlled modification of object prototype attributes. The attack may be initiated remotely. The reported GitHub issue was closed automatically due to inactivity.

🔗 References (8)