← Back to overview

A prototype pollution vulnerability was identified in jQWidgets up to version 24.0.1. The vulnerability affects the JQXLite.extend and jqxBaseFramework.extend functions within the jqwidgets/jqx-all.js file. Exploitation allows improperly controlled modification of object prototype attributes, a class of attack known as prototype pollution. The attack can be initiated remotely without requiring local access. The issue was reported via GitHub but was closed with the label 'not planned', indicating the vendor does not intend to fix the vulnerability. This leaves users of jQWidgets potentially exposed to remote exploitation. Prototype pollution can lead to denial of service, property injection, or in some cases remote code execution depending on the application context.

Affected products

  • jQWidgets up to 24.0.1

Related CVE's

  • CVE-2026-78178

Categories

  • Web Technologies