← Terug naar overzicht

A prototype pollution vulnerability has been identified in jQWidgets up to version 24.0.1. The flaw exists in the JQXLite.extend and jqxBaseFramework.extend functions within the jqwidgets/jqx-all.js file. The vulnerability allows improperly controlled modification of object prototype attributes, a class of attack commonly known as prototype pollution. The attack can be initiated remotely without requiring physical access to the target system. The issue was reported via GitHub but was closed with the label 'not planned', indicating the vendor does not intend to release a fix. This leaves users of affected versions potentially exposed to exploitation. Prototype pollution vulnerabilities can lead to denial of service, property injection, or in some cases remote code execution depending on the application context. Organizations using jQWidgets should assess their exposure and consider mitigations or alternative libraries.

Affected products

  • jQWidgets up to 24.0.1

Related CVE's

  • CVE-2026-78178

Categories

  • Web Technologies