PT-2026-79814 · Unknown · Phaser3-Rex-Notes
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
rexrainbow phaser3-rex-notes versions prior to 1.80.18
Description
A remote attack is possible through the BehaviorTree Blackboard Data Interface component. Specifically, the
SetValue() function within the plugins/utils/object/SetValue.js file is susceptible to prototype pollution, where manipulation of the key argument allows for the improperly controlled modification of object prototype attributes.Recommendations
Update rexrainbow phaser3-rex-notes to version 1.80.18 or later.
As a temporary mitigation, restrict the use of the
SetValue() function until the update is applied.Fix
Prototype Pollution
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phaser3-Rex-Notes