CVE-2026-78179: Rexrainbow PHASER3-Rex-Notes

Medium severity, CVSS 6.3. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/utils/object/SetValue.js of the component BehaviorTree Blackboard Data Interface. Such manipulation of the argument key leads to improperly controlled modification of object prototype attributes. The attack can be launched remotely.

Affected products

  • Rexrainbow PHASER3-Rex-Notes: version 1.80.0 only; version 1.80.1 only; version 1.80.2 only; version 1.80.3 only; version 1.80.4 only; version 1.80.5 only; …

Published 2026-08-24. Last modified 2026-08-24.