CVE-2026-78178

7.3

jQWidgets · jQWidgets

A prototype pollution and code injection vulnerability exists in jQWidgets versions 24.0.0 and 24.0.1, allowing unauthenticated attackers to modify object attributes.

Executive summary

A critical prototype pollution and code injection vulnerability in jQWidgets versions 24.0.0 and 24.0.1 allows unauthenticated attackers to compromise application integrity.

Vulnerability

The software is susceptible to improper control of object prototype attributes and code injection. This vulnerability can be triggered by unauthenticated attackers over the network.

Business impact

Successful exploitation allows an attacker to inject malicious code or manipulate application logic by modifying object prototypes. With a CVSS score of 7.3, this high-severity flaw could lead to full application compromise, data theft, or unauthorized actions performed on behalf of legitimate users.

Remediation

Immediate Action: Upgrade to a version beyond 24.0.1 if available, or apply the specific security fixes provided by the vendor.

Proactive Monitoring: Inspect application logs for suspicious input patterns, particularly those involving unexpected JSON payloads or object manipulations.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block common prototype pollution attack vectors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the ease of exploitation for unauthenticated users, this vulnerability should be remediated immediately. Organizations using jQWidgets should verify their current version and apply the necessary updates to prevent potential code injection and application-wide compromise.