CVE-2026-78179

Summary

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.

Affected Software

VendorProductVersion RangeStatus
rexrainbowphaser3-rex-notes1.80.0affected
rexrainbowphaser3-rex-notes1.80.1affected
rexrainbowphaser3-rex-notes1.80.2affected
rexrainbowphaser3-rex-notes1.80.3affected
rexrainbowphaser3-rex-notes1.80.4affected
rexrainbowphaser3-rex-notes1.80.5affected
rexrainbowphaser3-rex-notes1.80.6affected
rexrainbowphaser3-rex-notes1.80.7affected
rexrainbowphaser3-rex-notes1.80.8affected
rexrainbowphaser3-rex-notes1.80.9affected
rexrainbowphaser3-rex-notes1.80.10affected
rexrainbowphaser3-rex-notes1.80.11affected
rexrainbowphaser3-rex-notes1.80.12affected
rexrainbowphaser3-rex-notes1.80.13affected
rexrainbowphaser3-rex-notes1.80.14affected
rexrainbowphaser3-rex-notes1.80.15affected
rexrainbowphaser3-rex-notes1.80.16affected
rexrainbowphaser3-rex-notes1.80.17affected

Weaknesses

  • CWE-1321: Improperly Controlled Modification of Object Prototype Attributes
  • CWE-94: Code Injection

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References