CVE-2026-78178

Summary

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".

Affected Software

VendorProductVersion RangeStatus
n/ajQWidgets24.0.0affected
n/ajQWidgets24.0.1affected

Weaknesses

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes
  • CWE-94: Code Injection

References