PT-2026-79814 · Unknown · Phaser3-Rex-Notes

·

CVE-2026-78179

·

Published

2026-08-24

·

Updated

2026-08-24

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions rexrainbow phaser3-rex-notes versions prior to 1.80.18
Description A remote attack is possible through the BehaviorTree Blackboard Data Interface component. Specifically, the SetValue() function within the plugins/utils/object/SetValue.js file is susceptible to prototype pollution, where manipulation of the key argument allows for the improperly controlled modification of object prototype attributes.
Recommendations Update rexrainbow phaser3-rex-notes to version 1.80.18 or later. As a temporary mitigation, restrict the use of the SetValue() function until the update is applied.

Fix

Prototype Pollution

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-78179

Affected Products

Phaser3-Rex-Notes