CVE-2026-78178Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-all.js. This manipulation causes improperly controlled modification of object prototype attributes. The attack can be initiated remotely. The reported GitHub issue was closed with the label "not planned".

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1321

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-24: 2Technical Details · 2026-08-24: 108-24
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • SecNews@SecNews_GR
    Disclosure

    Κρίσιμη ευπάθεια jQWidgets: CVE-2026-78178 και prototype pollution https://secn.ws/2dVNZY

    Post summary

    The post announces the discovery of a critical prototype‑pollution vulnerability in jQWidgets, identified as CVE‑2026‑78178.

    00000144
    7.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-78178 Improper Object Prototype Attribute Modification in jQWidgets Up To 24.0.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-78178

    Post summary

    The post announces CVE‑2026‑78178 as an improper object prototype modification issue in jQWidgets up to 24.0.1, providing only the basic vulnerability label without PoC, exploit, or patch details.

    00000111
    4.1K followersView on X

Explore more