CVE-2026-78179: rexrainbow phaser3-rex-notes BehaviorTree Blackboard Data SetValue.js SetValue prototype pollution
A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Deployments using rexrainbow phaser3-rex-notes version 1.80.17 or earlier should be prioritized, particularly where the BehaviorTree Blackboard Data Interface is exposed to remotely supplied input.
What level of access does an attacker need?
The supplied CVSS vector indicates network-reachable exploitation with low privileges required and no user interaction. Exploitation involves controlling the key argument passed to SetValue.js.