CVE-2026-78179

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.

Scoring

Severity
MEDIUM
CVSS base score
6.5
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
EPSS probability
0.33%
CWE
CWE-1321, CWE-94
Published
2026-08-24
Last modified
2026-08-24

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs