Junglewise Threat Intelligence

CVE-2026-78178: jQWidgets prototype pollution in JQXLite.extend

CVE-2026-78178 · Severity: high · CVSS 7.3 · Published 2026-08-24

Executive brief

jQWidgets is a popular JavaScript UI component framework used to build rich web applications. A prototype pollution vulnerability in the framework's deep merge helper function allows an attacker to modify core JavaScript object properties if the application passes untrusted data into the merge function, potentially causing application malfunction, data corruption, or denial of service.

Technical details

This is a prototype pollution vulnerability in the JQXLite.extend() and jqxBaseFramework.extend() functions within jqwidgets/jqx-all.js. The vulnerable code implements an unsafe jQuery-style recursive merge that fails to reject dangerous keys like __proto__, constructor, and prototype before reading from or writing to objects during the merge process. When processing these special keys, the merge operation can write attacker-controlled properties into Object.prototype itself. The vulnerability is network-reachable and requires the application to pass untrusted or partially untrusted objects to the exposed merge helper functions. Successful exploitation can pollute the global object prototype, corrupt inherited properties, and alter application behavior or cause denial of service. The vulnerability was reported on 2026-07-05 but the issue was closed as "not planned" by the maintainers.

Affected products

  • jQWidgets jQWidgets up to 24.0.1

Timeline

  • 2026-07-05: disclosed: Vulnerability reported on GitHub issue #764
  • 2026-08-24: advisory: CVE-2026-78178 published

References