CVE-2026-78179
rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValue prototype pollution
CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.
| CWE | CWE-1321 CWE-94 |
| Vendor | rexrainbow |
| Product | phaser3-rex-notes |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for rexrainbow phaser3-rex-notes
Be the first to know when new medium vulnerabilities affecting rexrainbow phaser3-rex-notes are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
rexrainbow / phaser3-rex-notes
1.80.0 1.80.1 1.80.2 1.80.3 1.80.4 1.80.5 1.80.6 1.80.7 1.80.8 1.80.9 1.80.10 1.80.11 1.80.12 1.80.13 1.80.14 1.80.15 1.80.16 1.80.17
References
vuldb.com: https://vuldb.com/vuln/394563 vuldb.com: https://vuldb.com/vuln/394563/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78179 vuldb.com: https://vuldb.com/submit/884183 github.com: https://github.com/rexrainbow/phaser3-rex-notes/issues/572 github.com: https://github.com/rexrainbow/phaser3-rex-notes/
Credits
๐ wjm3 (VulDB User)