CVE-2026-78178: jQWidgets jqx-all.js jqxBaseFramework.extend prototype pollution
A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".
Affected Software
Event History
Frequently Asked Questions
Which deployments should be considered affected?
Deployments using jQWidgets versions up to and including 24.0.1 should be considered affected when they include jqwidgets/jqx-all.js.
Does exploitation require authentication or user interaction?
The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required. The issue can be initiated remotely.
Is a vendor fix or planned remediation identified?
No fix is identified in the provided data. The reported GitHub issue was closed with the label "not planned".