CVE-2026-78179 PUBLISHED

rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValue prototype pollution

Assigner: VulDB
Reserved: 23.08.2026 Published: 24.08.2026 Updated: 24.08.2026

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
CVSS Score: 5.3

Product Status

Vendor rexrainbow
Product phaser3-rex-notes
Versions
  • Version 1.80.0 is affected
  • Version 1.80.1 is affected
  • Version 1.80.2 is affected
  • Version 1.80.3 is affected
  • Version 1.80.4 is affected
  • Version 1.80.5 is affected
  • Version 1.80.6 is affected
  • Version 1.80.7 is affected
  • Version 1.80.8 is affected
  • Version 1.80.9 is affected
  • Version 1.80.10 is affected
  • Version 1.80.11 is affected
  • Version 1.80.12 is affected
  • Version 1.80.13 is affected
  • Version 1.80.14 is affected
  • Version 1.80.15 is affected
  • Version 1.80.16 is affected
  • Version 1.80.17 is affected

Credits

  • wjm3 (VulDB User) reporter

References

Problem Types

  • Improperly Controlled Modification of Object Prototype Attributes CWE
  • Code Injection CWE