A security flaw has been identified in alibaba-fusion next up to version 1.27.34. The vulnerability exists in the ConfigProvider.getContextProps function within components/dialog/index.tsx, specifically in the deepMerge component. An attacker can manipulate the locale argument to cause improperly controlled modification of object prototype attributes, a class of vulnerability known as prototype pollution. The attack can be initiated remotely without requiring local access. The issue was reported on GitHub but was automatically closed due to inactivity, suggesting it may remain unpatched. This type of vulnerability can potentially allow attackers to alter application behavior, bypass security controls, or cause denial of service.